Audit-Verlauf
analyzing-component-quality - 6 Audits
Audit-Version 6
Neueste Mittleres RisikoJun 28, 2026, 06:06 PM
Static analysis reported many command, weak-crypto, credential, and network patterns, but review found most are markdown examples or scoring text. No prompt injection, obfuscation, credential access, or network exfiltration was found. The remaining concern is that the skill grants Bash and ships a helper script that reads a caller-provided local path.
Probleme mit mittlerem Risiko (1)
Probleme mit niedrigem Risiko (3)
Risikofaktoren
⚡ Enthält Skripte (2)
📁 Dateisystemzugriff (2)
⚙️ Externe Befehle (3)
🌐 Netzwerkzugriff (1)
Erkannte Muster
Audit-Version 5
Niedriges RisikoJan 16, 2026, 07:29 PM
All 234 static findings are FALSE POSITIVES. The scanner incorrectly flagged documentation examples (YAML frontmatter with allowed-tools including Bash), educational security discussions, and security warning strings as actual security threats. The skill is a pure quality analysis tool with Read-only tool access. The quality-scorer.py script only reads local files for heuristic analysis and outputs text reports. No network operations, no external command execution, no credential access.
Risikofaktoren
📁 Dateisystemzugriff (2)
⚡ Enthält Skripte (1)
Audit-Version 4
Niedriges RisikoJan 16, 2026, 07:29 PM
All 234 static findings are FALSE POSITIVES. The scanner incorrectly flagged documentation examples (YAML frontmatter with allowed-tools including Bash), educational security discussions, and security warning strings as actual security threats. The skill is a pure quality analysis tool with Read-only tool access. The quality-scorer.py script only reads local files for heuristic analysis and outputs text reports. No network operations, no external command execution, no credential access.
Risikofaktoren
📁 Dateisystemzugriff (2)
⚡ Enthält Skripte (1)
Audit-Version 3
Niedriges RisikoJan 10, 2026, 11:44 AM
Pure quality analysis skill with no malicious capabilities. The Python script reads local files for heuristic analysis only. No network operations, no external command execution, no credential access.
Risikofaktoren
⚡ Enthält Skripte (1)
📁 Dateisystemzugriff (2)
Audit-Version 2
Niedriges RisikoJan 10, 2026, 11:44 AM
Pure quality analysis skill with no malicious capabilities. The Python script reads local files for heuristic analysis only. No network operations, no external command execution, no credential access.
Risikofaktoren
⚡ Enthält Skripte (1)
📁 Dateisystemzugriff (2)
Audit-Version 1
Niedriges RisikoJan 10, 2026, 11:44 AM
Pure quality analysis skill with no malicious capabilities. The Python script reads local files for heuristic analysis only. No network operations, no external command execution, no credential access.