📦

Audit-Verlauf

commit-helper - 9 Audits

Versionsvergleich

Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.

VersionDatumErgebnisPrüfelementeÄnderung ggü. vorheriger
v9 Neueste23. Juli 2026, 09:47 Keine bestätigten Befunde0Keine Änderung der Fähigkeiten
v8 8. Juli 2026, 00:08 Keine bestätigten Befunde0Keine Änderung der Fähigkeiten
v7 5. Juli 2026, 05:22 Keine bestätigten Befunde0Keine Änderung der Fähigkeiten
v6 28. Juni 2026, 18:44 2 bestätigt0 Dateisystemzugriff
v5 16. Jan. 2026, 20:00 Keine bestätigten Befunde0Keine Änderung der Fähigkeiten
v4 16. Jan. 2026, 20:00 Keine bestätigten Befunde0Netzwerkzugriff
v3 10. Jan. 2026, 11:47 Keine bestätigten Befunde0Keine Änderung der Fähigkeiten
v2 10. Jan. 2026, 11:47 Keine bestätigten Befunde0Keine Änderung der Fähigkeiten
v1 10. Jan. 2026, 11:47 Keine bestätigten Befunde0Ausgangsbasis

8. Juli 2026, 00:08

The static findings are false positives caused by Markdown code fences, inline commit-format examples, read-only git inspection commands, and a documentation URL. No prompt injection, exfiltration intent, destructive command, or hidden execution path was found in the reviewed files.

6
Gescannte Dateien
852
Analysierte Zeilen
2
Prüfelemente
0
Falschmeldungen ignoriert
Geprüft von: codex

5. Juli 2026, 05:22

Static analysis flagged many command patterns, but review found they are Markdown examples, inline Conventional Commit syntax, and copyable git commit snippets. The hardcoded URL is a public documentation link, and no prompt injection, hidden execution, network exfiltration, or reconnaissance intent was found.

6
Gescannte Dateien
852
Analysierte Zeilen
2
Prüfelemente
0
Falschmeldungen ignoriert
Geprüft von: codex

28. Juni 2026, 18:44

Static analysis reported many external command, weak crypto, PowerShell, and network patterns. Review found the command patterns are legitimate git workflow guidance, while the weak crypto and PowerShell hits are Markdown and template false positives. No evidence found of prompt injection, credential access, data exfiltration, or malicious intent.

6
Gescannte Dateien
852
Analysierte Zeilen
4
Prüfelemente
3
Falschmeldungen ignoriert

Bestätigte Sicherheitsbedenken (2)

Mittel
Git Command Execution Guidance
The skill instructs the assistant to use Bash for git status and diff inspection, then suggests git commit commands. This is expected for a commit helper, but it can read repository diffs and create commits when commands are executed.
The referenced lines explicitly direct Bash use for git inspection and show git commit commands. The context is a commit assistant, so the risk is real but consistent with the declared purpose.
Mittel
Copy-Paste Shell Commit Templates
Several examples use shell command substitution and heredoc syntax to create multiline commits. The quoted heredoc pattern reduces shell expansion risk, but users should review generated commands before execution.
The exact shell patterns are present in Markdown examples and can execute git commit if copied. They are not hidden or malicious, but they are still executable shell guidance.
Statische falsch positive Treffer ignoriert (3)

Diese statischen Treffer wurden durch semantische Prüfung verworfen oder entsprachen reinen Schema-Tokens; daher werden sie aus Transparenzgründen angezeigt, beeinflussen jedoch nicht die Qualitätsbewertung.

Niedrig
External Documentation Link Is Benign
The hardcoded URL points to the public Conventional Commits documentation. It is a Markdown reference link, not code that performs a network request.
The line contains only a Markdown documentation link. No fetch, curl, wget, or other network call was found in the reviewed files.
Niedrig
Weak Cryptography Detections Are False Positives
The static weak-crypto hits occur in prose, placeholders, and Conventional Commit examples such as description rules. No cryptographic APIs, hash implementations, or encryption routines were found.
The cited locations define commit-message description style and validation rules, not cryptographic behavior. The repository contains Markdown and text templates rather than executable crypto code.
Niedrig
PowerShell Detection Is Documentation Context
The PowerShell hit appears inside an example diff and a proposed documentation commit body. It does not instruct the skill to run PowerShell during normal operation.
The lines are inside a Markdown example showing documentation changes. They are not part of an operational workflow or executable script.

Erkannte Muster

Bash-Based Git InspectionGenerated Git Commit Commands
Geprüft von: codex

16. Jan. 2026, 20:00

Pure prompt-based skill with no executable code. All 249 static findings are false positives: documentation examples showing git commands (not execution), commit message format strings misinterpreted as cryptographic patterns, and version strings flagged as C2 keywords. This is a safe documentation skill.

7
Gescannte Dateien
1,094
Analysierte Zeilen
3
Prüfelemente
0
Falschmeldungen ignoriert

Risikofaktoren

⚙️ Externe Befehle (3)
📁 Dateisystemzugriff (1)
🌐 Netzwerkzugriff (1)
Geprüft von: claude

16. Jan. 2026, 20:00

Pure prompt-based skill with no executable code. All 249 static findings are false positives: documentation examples showing git commands (not execution), commit message format strings misinterpreted as cryptographic patterns, and version strings flagged as C2 keywords. This is a safe documentation skill.

7
Gescannte Dateien
1,094
Analysierte Zeilen
3
Prüfelemente
0
Falschmeldungen ignoriert

Risikofaktoren

⚙️ Externe Befehle (3)
📁 Dateisystemzugriff (1)
🌐 Netzwerkzugriff (1)
Geprüft von: claude

10. Jan. 2026, 11:47

Pure prompt-based skill with no executable code. Uses git commands through Bash tool for change analysis, which is necessary for its purpose. No network calls, no file writes, no persistence mechanisms.

6
Gescannte Dateien
852
Analysierte Zeilen
2
Prüfelemente
0
Falschmeldungen ignoriert

Risikofaktoren

⚙️ Externe Befehle (2)
📁 Dateisystemzugriff (1)
Geprüft von: claude

10. Jan. 2026, 11:47

Pure prompt-based skill with no executable code. Uses git commands through Bash tool for change analysis, which is necessary for its purpose. No network calls, no file writes, no persistence mechanisms.

6
Gescannte Dateien
852
Analysierte Zeilen
2
Prüfelemente
0
Falschmeldungen ignoriert

Risikofaktoren

⚙️ Externe Befehle (2)
📁 Dateisystemzugriff (1)
Geprüft von: claude

10. Jan. 2026, 11:47

Pure prompt-based skill with no executable code. Uses git commands through Bash tool for change analysis, which is necessary for its purpose. No network calls, no file writes, no persistence mechanisms.

6
Gescannte Dateien
852
Analysierte Zeilen
2
Prüfelemente
0
Falschmeldungen ignoriert

Risikofaktoren

⚙️ Externe Befehle (2)
📁 Dateisystemzugriff (1)
Geprüft von: claude