監査履歴
security-guardian - 11 監査
バージョン比較
監査済みバージョン間の機能と検出結果の変化(新しい順)。
| バージョン | 日付 | 結果 | レビュー項目 | 前バージョンとの変化 |
|---|---|---|---|---|
| v11 最新 | 21. Juli 2026, 10:02 | 確認された検出結果なし | 0 | 機能の変化なし |
| v10 | 19. Juli 2026, 02:14 | 2 確認済み | 0 | 機能の変化なし |
| v9 | 7. Juli 2026, 19:21 | 確認された検出結果なし | 0 | 機能の変化なし |
| v8 | 5. Juli 2026, 04:09 | 確認された検出結果なし | 0 | 機能の変化なし |
| v7 | 5. Juli 2026, 04:09 | 確認された検出結果なし | 0 | 機能の変化なし |
| v6 | 28. Juni 2026, 15:16 | 1 確認済み | 1 | 環境変数 |
| v5 | 16. Jan. 2026, 19:37 | 確認された検出結果なし | 0 | 機能の変化なし |
| v4 | 16. Jan. 2026, 19:37 | 確認された検出結果なし | 0 | 外部コマンドネットワークアクセススクリプトを含むファイルシステムへのアクセス |
| v3 | 10. Jan. 2026, 11:28 | 確認された検出結果なし | 0 | 機能の変化なし |
| v2 | 10. Jan. 2026, 11:28 | 確認された検出結果なし | 0 | 機能の変化なし |
| v1 | 10. Jan. 2026, 11:28 | 確認された検出結果なし | 0 | 基準 |
21. Juli 2026, 10:02
All 400 static matches are false positives in a French-language application-security reference skill. The flagged strings appear in educational examples, checklists, or defensive detection guidance, and no executable code, credential access, or outbound network behavior was found. No prompt-injection text was found in the reviewed skill instructions.
リスク要因
🌐 ネットワークアクセス (50)
📁 ファイルシステムへのアクセス (30)
🔑 環境変数 (1)
⚙️ 外部コマンド (47)
⚡ スクリプトを含む (32)
19. Juli 2026, 02:14
All 398 static detections are Markdown examples, checklist terms, or inline references; no packaged executable code performs the flagged actions. Two examples labeled correct contain unsafe remediation patterns that could introduce path traversal or XXE if copied. No prompt injection or malicious exfiltration intent was found.
確認済みのセキュリティ上の懸念 (2)
リスク要因
🌐 ネットワークアクセス (50)
📁 ファイルシステムへのアクセス (30)
🔑 環境変数 (1)
⚙️ 外部コマンド (47)
⚡ スクリプトを含む (32)
7. Juli 2026, 19:21
All 399 static findings were adjudicated as false positives after reviewing the Markdown context. The flagged strings are educational vulnerability examples, checklists, or remediation guidance, not executable code or credential access flows. No evidence found for prompt injection, data exfiltration intent, or malicious instructions.
リスク要因
🌐 ネットワークアクセス (97)
📁 ファイルシステムへのアクセス (30)
🔑 環境変数 (1)
⚙️ 外部コマンド (47)
⚡ スクリプトを含む (32)
5. Juli 2026, 04:09
The static findings are false positives caused by Markdown security documentation, exploit payload examples, and defensive checklists. I found no executable package code, no credential exfiltration flow, and no prompt injection attempt in the reviewed files.
静的解析の誤検知を無視 (147)
これらの静的マッチはセマンティックレビューで却下されたか、スキーマのみのトークンに一致したため、透明性のために表示されていますが、品質スコアには影響しません。
リスク要因
🌐 ネットワークアクセス (97)
📁 ファイルシステムへのアクセス (30)
🔑 環境変数 (1)
⚙️ 外部コマンド (47)
⚡ スクリプトを含む (32)
5. Juli 2026, 04:09
The static findings are false positives caused by Markdown security documentation, exploit payload examples, and defensive checklists. I found no executable package code, no credential exfiltration flow, and no prompt injection attempt in the reviewed files.
静的解析の誤検知を無視 (147)
これらの静的マッチはセマンティックレビューで却下されたか、スキーマのみのトークンに一致したため、透明性のために表示されていますが、品質スコアには影響しません。
リスク要因
🌐 ネットワークアクセス (97)
📁 ファイルシステムへのアクセス (30)
🔑 環境変数 (1)
⚙️ 外部コマンド (47)
⚡ スクリプトを含む (32)
28. Juni 2026, 15:16
Static analysis detected many dangerous command, network, filesystem, script, and secret patterns. Manual review found these are primarily security-training examples and audit checklists, not executable code or hidden exfiltration. The skill is publishable with a medium dual-use warning because it documents exploit payloads and sensitive target examples.
確認済みのセキュリティ上の懸念 (1)
レビューが必要な検出事項 (1)
これらの検出事項は不確実なレガシー監査判定に基づくため、レビューが必要ですが、確認済みのセキュリティ問題としてはカウントされません。
静的解析の誤検知を無視 (3)
これらの静的マッチはセマンティックレビューで却下されたか、スキーマのみのトークンに一致したため、透明性のために表示されていますが、品質スコアには影響しません。
リスク要因
⚙️ 外部コマンド (3)
🌐 ネットワークアクセス (3)
⚡ スクリプトを含む (3)
📁 ファイルシステムへのアクセス (3)
🔑 環境変数 (1)
検出されたパターン
16. Jan. 2026, 19:37
This skill is purely security documentation and guidance. All 1546 static findings are FALSE POSITIVES because they come from markdown documentation files containing examples of vulnerable code patterns for educational purposes. The skill provides read-only analysis tools (Read, Grep, Glob, Bash) to help developers identify and fix security issues.
リスク要因
🌐 ネットワークアクセス (2)
📁 ファイルシステムへのアクセス (2)
16. Jan. 2026, 19:37
This skill is purely security documentation and guidance. All 1546 static findings are FALSE POSITIVES because they come from markdown documentation files containing examples of vulnerable code patterns for educational purposes. The skill provides read-only analysis tools (Read, Grep, Glob, Bash) to help developers identify and fix security issues.
リスク要因
🌐 ネットワークアクセス (2)
📁 ファイルシステムへのアクセス (2)
10. Jan. 2026, 11:28
Pure prompt-based skill containing only markdown documentation about security best practices. No executable code, no scripts, no network operations, no data collection. Provides educational guidance on OWASP Top 10, authentication, authorization, cryptography, and vulnerability detection.
10. Jan. 2026, 11:28
Pure prompt-based skill containing only markdown documentation about security best practices. No executable code, no scripts, no network operations, no data collection. Provides educational guidance on OWASP Top 10, authentication, authorization, cryptography, and vulnerability detection.
10. Jan. 2026, 11:28
Pure prompt-based skill containing only markdown documentation about security best practices. No executable code, no scripts, no network operations, no data collection. Provides educational guidance on OWASP Top 10, authentication, authorization, cryptography, and vulnerability detection.