История аудитов
debug-cuda-crash - 8 аудиты
Сравнение версий
Изменения возможностей и находок между проверенными версиями, сначала новые.
| Версия | Дата | Результат | Пункты проверки | Изменение к предыдущей |
|---|---|---|---|---|
| v8 Последняя | 23. Juli 2026, 17:47 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v7 | 8. Juli 2026, 01:52 | 1 подтверждено | 0 | Возможности не изменились |
| v6 | 6. Juli 2026, 15:05 | 1 подтверждено | 0 | Возможности не изменились |
| v5 | 30. Juni 2026, 00:46 | Подтверждённых находок нет | 2 | Внешние команды Содержит скрипты |
| v4 | 17. Jan. 2026, 05:25 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v3 | 17. Jan. 2026, 05:25 | Подтверждённых находок нет | 0 | Содержит скрипты |
| v2 | 6. Jan. 2026, 07:41 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v1 | 6. Jan. 2026, 07:41 | Подтверждённых находок нет | 0 | Базовая |
23. Juli 2026, 17:47
All 127 static findings are false positives caused by Markdown code formatting, example commands, and benign CUDA terminology. The skill is a documentation-only tutorial, and no prompt injection, automatic execution, reconnaissance, or malicious intent was found.
Факторы риска
⚙️ Внешние команды (50)
8. Juli 2026, 01:52
The static external-command and blocker findings are false positives caused by Markdown backticks, fenced examples, CUDA sample code, and diagnostic-tool documentation. No prompt injection, malicious automation, or unauthorized command execution was found in the reviewed skill file. A low residual concern remains because debug logs may contain sensitive tensor metadata or system details.
Подтверждённые проблемы безопасности (1)
Факторы риска
⚙️ Внешние команды (122)
6. Juli 2026, 15:05
The static external-command alerts are false positives caused by Markdown backticks and fenced tutorial examples, not executable Ruby or shell code. I found no prompt injection or malicious exfiltration intent. The main residual issue is that local debug logs may contain sensitive tensor metadata, statistics, or system details.
Подтверждённые проблемы безопасности (1)
Факторы риска
⚙️ Внешние команды (122)
30. Juni 2026, 00:46
Static analysis reported many external command and weak-crypto patterns, but review shows they are Markdown tutorial examples, environment variables, CUDA debugger commands, and sample output. No prompt injection, exfiltration, credential access, or executable skill code was found; the remaining risk is that users may run diagnostic commands and create logs containing sensitive metadata.
Пункты проверки возможностей (2)
Это реальные локальные возможности, которые могут ожидаться для этого навыка, поэтому они требуют проверки, но не считаются подтверждённым вредоносным поведением.
Статические ложные срабатывания проигнорированы (1)
Эти статические совпадения были отклонены семантической проверкой или совпадали только со схемными токенами, поэтому они показываются для прозрачности, но не влияют на оценку качества.
Факторы риска
⚙️ Внешние команды (5)
Обнаруженные паттерны
17. Jan. 2026, 05:25
All 160 static findings are FALSE POSITIVES. This skill contains ONLY markdown documentation with zero executable code. The 'backtick execution' findings flag markdown code block formatting, not shell commands. 'Weak cryptographic algorithm' findings flag hash identifiers in metadata. 'System reconnaissance' findings flag environment variable documentation. Pure educational content for CUDA debugging.
Факторы риска
⚡ Содержит скрипты (1)
17. Jan. 2026, 05:25
All 160 static findings are FALSE POSITIVES. This skill contains ONLY markdown documentation with zero executable code. The 'backtick execution' findings flag markdown code block formatting, not shell commands. 'Weak cryptographic algorithm' findings flag hash identifiers in metadata. 'System reconnaissance' findings flag environment variable documentation. Pure educational content for CUDA debugging.
Факторы риска
⚡ Содержит скрипты (1)
6. Jan. 2026, 07:41
This skill contains only markdown documentation. No executable code, network calls, filesystem access, or command execution. Pure educational content for debugging CUDA crashes.
6. Jan. 2026, 07:41
This skill contains only markdown documentation. No executable code, network calls, filesystem access, or command execution. Pure educational content for debugging CUDA crashes.