История аудитов
agent-fungibility - 9 аудиты
Сравнение версий
Изменения возможностей и находок между проверенными версиями, сначала новые.
| Версия | Дата | Результат | Пункты проверки | Изменение к предыдущей |
|---|---|---|---|---|
| v9 Последняя | 6. Juli 2026, 12:09 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v8 | 6. Juli 2026, 12:09 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v7 | 29. Juni 2026, 17:01 | Подтверждённых находок нет | 2 | Внешние команды |
| v6 | 21. Jan. 2026, 17:04 | Подтверждённых находок нет | 0 | Внешние команды |
| v5 | 17. Jan. 2026, 03:50 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v4 | 17. Jan. 2026, 03:50 | Подтверждённых находок нет | 0 | Внешние команды |
| v3 | 10. Jan. 2026, 13:55 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v2 | 10. Jan. 2026, 13:55 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v1 | 10. Jan. 2026, 13:55 | Подтверждённых находок нет | 0 | Базовая |
6. Juli 2026, 12:09
All six static findings are false positives from Markdown inline code and fenced command examples. The skill describes manual BV and NTM commands, but it does not execute code, use dynamic shell input, or show malicious intent. No evidence found for prompt injection, data exfiltration, or business-logic abuse in SKILL.md.
Факторы риска
⚙️ Внешние команды (6)
6. Juli 2026, 12:09
All six static findings are false positives from Markdown inline code and fenced command examples. The skill describes manual BV and NTM commands, but it does not execute code, use dynamic shell input, or show malicious intent. No evidence found for prompt injection, data exfiltration, or business-logic abuse in SKILL.md.
Факторы риска
⚙️ Внешние команды (6)
29. Juni 2026, 17:01
Static analysis flagged shell command examples, a Windows SAM keyword match, and weak cryptography keyword matches. Manual review found no executable skill code, no credential access, and no cryptographic implementation; the issues are documentation examples or prose false positives. The skill is low risk, with a warning that users should review local command examples before running them.
Пункты проверки возможностей (2)
Это реальные локальные возможности, которые могут ожидаться для этого навыка, поэтому они требуют проверки, но не считаются подтверждённым вредоносным поведением.
Статические ложные срабатывания проигнорированы (2)
Эти статические совпадения были отклонены семантической проверкой или совпадали только со схемными токенами, поэтому они показываются для прозрачности, но не влияют на оценку качества.
Факторы риска
⚙️ Внешние команды (7)
Обнаруженные паттерны
21. Jan. 2026, 17:04
All 31 static findings are false positives. The skill is pure documentation about multi-agent system design philosophy. No executable code, no network calls, no credential handling. Static analyzer flagged markdown code formatting (backticks) and common English words as security issues.
17. Jan. 2026, 03:50
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Факторы риска
⚙️ Внешние команды (7)
Обнаруженные паттерны
17. Jan. 2026, 03:50
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Факторы риска
⚙️ Внешние команды (7)
Обнаруженные паттерны
10. Jan. 2026, 13:55
Pure documentation skill containing only markdown content about agent fungibility philosophy. No executable code, scripts, network calls, filesystem access, or external command execution. This is a prompt-based skill with zero security risk.
10. Jan. 2026, 13:55
Pure documentation skill containing only markdown content about agent fungibility philosophy. No executable code, scripts, network calls, filesystem access, or external command execution. This is a prompt-based skill with zero security risk.
10. Jan. 2026, 13:55
Pure documentation skill containing only markdown content about agent fungibility philosophy. No executable code, scripts, network calls, filesystem access, or external command execution. This is a prompt-based skill with zero security risk.