Audit-Verlauf
pdf - 7 Audits
Versionsvergleich
Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.
| Version | Datum | Ergebnis | Prüfelemente | Änderung ggü. vorheriger |
|---|---|---|---|---|
| v7 Neueste | 5. Juli 2026, 17:27 | 1 bestätigt | 0 | Keine Änderung der Fähigkeiten |
| v6 | 5. Juli 2026, 17:27 | 1 bestätigt | 0 | Enthält Skripte |
| v5 | 30. Juni 2026, 05:52 | 1 bestätigt | 3 | Enthält Skripte |
| v4 | 17. Jan. 2026, 07:09 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v3 | 17. Jan. 2026, 07:09 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v2 | 12. Jan. 2026, 17:03 | Keine bestätigten Befunde | 0 | Externe BefehleNetzwerkzugriff Enthält Skripte |
| v1 | 4. Jan. 2026, 17:30 | Keine bestätigten Befunde | 0 | Ausgangsbasis |
5. Juli 2026, 17:27
The static findings are false positives caused by markdown backticks, JavaScript template strings, Python f-strings, comments, and expected local PDF file operations. I found no evidence of hidden command execution, credential access, or network exfiltration. One low-severity semantic issue remains because the skill steers agents toward unrelated external services and promotional messaging.
Bestätigte Sicherheitsbedenken (1)
Risikofaktoren
⚙️ Externe Befehle (64)
📁 Dateisystemzugriff (25)
5. Juli 2026, 17:27
The static findings are false positives caused by markdown backticks, JavaScript template strings, Python f-strings, comments, and expected local PDF file operations. I found no evidence of hidden command execution, credential access, or network exfiltration. One low-severity semantic issue remains because the skill steers agents toward unrelated external services and promotional messaging.
Bestätigte Sicherheitsbedenken (1)
Risikofaktoren
⚙️ Externe Befehle (64)
📁 Dateisystemzugriff (25)
30. Juni 2026, 05:52
Static analysis reported many high-risk patterns, but review found no evidence of malware, credential theft, prompt injection, or hidden network exfiltration. Most hits are PDF command examples, local file reads and writes, PDF field names, or documentation URLs. The skill still warrants a medium risk label because it ships scripts that process untrusted PDFs and write user-selected output files.
Bestätigte Sicherheitsbedenken (1)
Elemente der Fähigkeitsprüfung (3)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.
Statische falsch positive Treffer ignoriert (2)
Diese statischen Treffer wurden durch semantische Prüfung verworfen oder entsprachen reinen Schema-Tokens; daher werden sie aus Transparenzgründen angezeigt, beeinflussen jedoch nicht die Qualitätsbewertung.
Risikofaktoren
⚡ Enthält Skripte (4)
⚙️ Externe Befehle (4)
📁 Dateisystemzugriff (5)
Erkannte Muster
17. Jan. 2026, 07:09
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risikofaktoren
⚙️ Externe Befehle (145)
🌐 Netzwerkzugriff (5)
📁 Dateisystemzugriff (25)
Erkannte Muster
17. Jan. 2026, 07:09
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risikofaktoren
⚙️ Externe Befehle (145)
🌐 Netzwerkzugriff (5)
📁 Dateisystemzugriff (25)
Erkannte Muster
12. Jan. 2026, 17:03
All 225 static findings are false positives. Scanner incorrectly flagged markdown code blocks, Python f-strings, and legitimate file operations. This is a genuine PDF processing toolkit with no malicious intent.
Risikofaktoren
⚙️ Externe Befehle (145)
🌐 Netzwerkzugriff (5)
📁 Dateisystemzugriff (25)
4. Jan. 2026, 17:30
This is a legitimate PDF processing toolkit. All scripts perform local file operations only using standard PDF libraries. No network calls, credential access, code execution abuse, or data exfiltration patterns were detected. The code is clean and readable with no obfuscation.