Audit-Verlauf
commit-helper - 9 Audits
Versionsvergleich
Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.
| Version | Datum | Ergebnis | Prüfelemente | Änderung ggü. vorheriger |
|---|---|---|---|---|
| v9 Neueste | 23. Juli 2026, 09:47 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v8 | 8. Juli 2026, 00:08 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v7 | 5. Juli 2026, 05:22 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v6 | 28. Juni 2026, 18:44 | 2 bestätigt | 0 | Dateisystemzugriff |
| v5 | 16. Jan. 2026, 20:00 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v4 | 16. Jan. 2026, 20:00 | Keine bestätigten Befunde | 0 | Netzwerkzugriff |
| v3 | 10. Jan. 2026, 11:47 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v2 | 10. Jan. 2026, 11:47 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v1 | 10. Jan. 2026, 11:47 | Keine bestätigten Befunde | 0 | Ausgangsbasis |
23. Juli 2026, 09:47
All 67 static findings are false positives caused by Markdown formatting, documentation links, or intentional Git command examples. Quoted heredocs invoke only cat with literal bodies, while PowerShell and reconnaissance matches are prose or code-fence text. No prompt injection, data exfiltration, or concealed execution intent was found.
Risikofaktoren
⚙️ Externe Befehle (50)
🌐 Netzwerkzugriff (1)
8. Juli 2026, 00:08
The static findings are false positives caused by Markdown code fences, inline commit-format examples, read-only git inspection commands, and a documentation URL. No prompt injection, exfiltration intent, destructive command, or hidden execution path was found in the reviewed files.
Risikofaktoren
⚙️ Externe Befehle (64)
🌐 Netzwerkzugriff (1)
5. Juli 2026, 05:22
Static analysis flagged many command patterns, but review found they are Markdown examples, inline Conventional Commit syntax, and copyable git commit snippets. The hardcoded URL is a public documentation link, and no prompt injection, hidden execution, network exfiltration, or reconnaissance intent was found.
Risikofaktoren
⚙️ Externe Befehle (64)
🌐 Netzwerkzugriff (1)
28. Juni 2026, 18:44
Static analysis reported many external command, weak crypto, PowerShell, and network patterns. Review found the command patterns are legitimate git workflow guidance, while the weak crypto and PowerShell hits are Markdown and template false positives. No evidence found of prompt injection, credential access, data exfiltration, or malicious intent.
Bestätigte Sicherheitsbedenken (2)
Statische falsch positive Treffer ignoriert (3)
Diese statischen Treffer wurden durch semantische Prüfung verworfen oder entsprachen reinen Schema-Tokens; daher werden sie aus Transparenzgründen angezeigt, beeinflussen jedoch nicht die Qualitätsbewertung.
Risikofaktoren
⚙️ Externe Befehle (5)
🌐 Netzwerkzugriff (1)
Erkannte Muster
16. Jan. 2026, 20:00
Pure prompt-based skill with no executable code. All 249 static findings are false positives: documentation examples showing git commands (not execution), commit message format strings misinterpreted as cryptographic patterns, and version strings flagged as C2 keywords. This is a safe documentation skill.
Risikofaktoren
⚙️ Externe Befehle (3)
📁 Dateisystemzugriff (1)
🌐 Netzwerkzugriff (1)
16. Jan. 2026, 20:00
Pure prompt-based skill with no executable code. All 249 static findings are false positives: documentation examples showing git commands (not execution), commit message format strings misinterpreted as cryptographic patterns, and version strings flagged as C2 keywords. This is a safe documentation skill.
Risikofaktoren
⚙️ Externe Befehle (3)
📁 Dateisystemzugriff (1)
🌐 Netzwerkzugriff (1)
10. Jan. 2026, 11:47
Pure prompt-based skill with no executable code. Uses git commands through Bash tool for change analysis, which is necessary for its purpose. No network calls, no file writes, no persistence mechanisms.
Risikofaktoren
⚙️ Externe Befehle (2)
📁 Dateisystemzugriff (1)
10. Jan. 2026, 11:47
Pure prompt-based skill with no executable code. Uses git commands through Bash tool for change analysis, which is necessary for its purpose. No network calls, no file writes, no persistence mechanisms.
Risikofaktoren
⚙️ Externe Befehle (2)
📁 Dateisystemzugriff (1)
10. Jan. 2026, 11:47
Pure prompt-based skill with no executable code. Uses git commands through Bash tool for change analysis, which is necessary for its purpose. No network calls, no file writes, no persistence mechanisms.