Audit-Verlauf
claude-reflect - 10 Audits
Versionsvergleich
Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.
| Version | Datum | Ergebnis | Prüfelemente | Änderung ggü. vorheriger |
|---|---|---|---|---|
| v10 Neueste | 21. Juli 2026, 10:00 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v9 | 18. Juli 2026, 14:34 | 2 bestätigt | 0 | Keine Änderung der Fähigkeiten |
| v8 | 7. Juli 2026, 17:39 | 3 bestätigt | 53 | UmgebungsvariablenEnthält Skripte |
| v7 | 5. Juli 2026, 04:52 | 13 bestätigt | 87 | Keine Änderung der Fähigkeiten |
| v6 | 28. Juni 2026, 13:58 | 1 bestätigt | 4 | UmgebungsvariablenNetzwerkzugriff |
| v5 | 16. Jan. 2026, 18:00 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v4 | 16. Jan. 2026, 18:00 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v3 | 10. Jan. 2026, 11:07 | Keine bestätigten Befunde | 1 | Keine Änderung der Fähigkeiten |
| v2 | 10. Jan. 2026, 11:07 | Keine bestätigten Befunde | 1 | Keine Änderung der Fähigkeiten |
| v1 | 10. Jan. 2026, 11:07 | Keine bestätigten Befunde | 1 | Ausgangsbasis |
21. Juli 2026, 10:00
claude-reflect is a documentation-only Claude Code plugin corpus (8 Markdown/text files, no executable scripts in scope). All 91 static findings were adjudicated as false positives: the `~/.claude/*` references are the plugin's own documented memory-hierarchy and queue storage, the two CRITICAL `rm -rf` hits are user-facing cache-clearing instructions scoped to a specific named plugin-cache subdirectory in the README troubleshooting section, the 'backtick execution' hits are Markdown inline-code/code-fence syntax, and the hardcoded URLs point to the project's own public repository. No prompt-injection, data-exfiltration, or business-logic-abuse intent was found.
Risikofaktoren
📁 Dateisystemzugriff (50)
⚙️ Externe Befehle (24)
18. Juli 2026, 14:34
All 72 static alerts are false positives after contextual review. Markdown formatting caused command alerts, GitHub links are documentation, and cache deletion targets only plugin-specific directories. Approved text can still alter persistent agent instructions, while correction capture and history scans may retain sensitive session content locally.
Bestätigte Sicherheitsbedenken (2)
Risikofaktoren
📁 Dateisystemzugriff (34)
⚙️ Externe Befehle (24)
7. Juli 2026, 17:39
The static command, network, and reconnaissance alerts are mostly markdown documentation false positives. The filesystem alerts are confirmed because the skill intentionally reads and writes Claude Code memory, rules, queues, settings, session history, and command files under hidden directories.
Bestätigte Sicherheitsbedenken (3)
Elemente der Fähigkeitsprüfung (53)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.
Risikofaktoren
📁 Dateisystemzugriff (53)
⚙️ Externe Befehle (24)
5. Juli 2026, 04:52
This skill intentionally reads and writes Claude Code memory files, queues user corrections, and can scan local session history under the user home directory. Most confirmed findings are privacy, local persistence, and external CLI analysis risks tied to the core feature, while documentation, tests, /dev/null redirects, and the reviewed JPEG asset are false positives. No evidence found of network exfiltration code or prompt-injection text that tries to bypass this audit.
Bestätigte Sicherheitsbedenken (13)
Elemente der Fähigkeitsprüfung (87)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.
Risikofaktoren
⚙️ Externe Befehle (71)
📁 Dateisystemzugriff (113)
🔑 Umgebungsvariablen (5)
🌐 Netzwerkzugriff (8)
Erkannte Muster
28. Juni 2026, 13:58
Static analysis reported a critical heuristic because the repository combines scripts, shell examples, home-directory file access, URLs, and secret-related terms. Manual review found no evidence of malicious C2, credential exfiltration, or prompt-injection text in the skill files, but confirmed a real elevated-risk design: hooks capture local prompts, /reflect can scan session history, and approved learnings are written to assistant guidance files. Publish with a clear privacy and file-modification warning.
Bestätigte Sicherheitsbedenken (1)
Elemente der Fähigkeitsprüfung (4)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.
Statische falsch positive Treffer ignoriert (1)
Diese statischen Treffer wurden durch semantische Prüfung verworfen oder entsprachen reinen Schema-Tokens; daher werden sie aus Transparenzgründen angezeigt, beeinflussen jedoch nicht die Qualitätsbewertung.
Risikofaktoren
⚡ Enthält Skripte (3)
📁 Dateisystemzugriff (3)
⚙️ Externe Befehle (3)
🔑 Umgebungsvariablen (2)
🌐 Netzwerkzugriff (3)
Erkannte Muster
16. Jan. 2026, 18:00
This is a legitimate self-learning system with no malicious intent. All static findings are false positives: shell commands are documentation examples, hidden file access targets the standard ~/.claude/ directory for Claude configuration, and credential references are guidance documentation, not actual access. The critical heuristic alert incorrectly flagged local file operations as dangerous.
Risikofaktoren
⚡ Enthält Skripte (2)
📁 Dateisystemzugriff (2)
⚙️ Externe Befehle (1)
16. Jan. 2026, 18:00
This is a legitimate self-learning system with no malicious intent. All static findings are false positives: shell commands are documentation examples, hidden file access targets the standard ~/.claude/ directory for Claude configuration, and credential references are guidance documentation, not actual access. The critical heuristic alert incorrectly flagged local file operations as dangerous.
Risikofaktoren
⚡ Enthält Skripte (2)
📁 Dateisystemzugriff (2)
⚙️ Externe Befehle (1)
10. Jan. 2026, 11:07
Legitimate self-learning system with minimal risk profile. All code execution is self-contained and serves the stated purpose of capturing user corrections. No network calls, no credential access, no data exfiltration.
Elemente der Fähigkeitsprüfung (1)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.
Risikofaktoren
⚡ Enthält Skripte (3)
📁 Dateisystemzugriff (2)
⚙️ Externe Befehle (2)
10. Jan. 2026, 11:07
Legitimate self-learning system with minimal risk profile. All code execution is self-contained and serves the stated purpose of capturing user corrections. No network calls, no credential access, no data exfiltration.
Elemente der Fähigkeitsprüfung (1)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.
Risikofaktoren
⚡ Enthält Skripte (3)
📁 Dateisystemzugriff (2)
⚙️ Externe Befehle (2)
10. Jan. 2026, 11:07
Legitimate self-learning system with minimal risk profile. All code execution is self-contained and serves the stated purpose of capturing user corrections. No network calls, no credential access, no data exfiltration.
Elemente der Fähigkeitsprüfung (1)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.