سجل التدقيق
component-refactoring - 6 عمليات التدقيق
مقارنة الإصدارات
التغييرات في القدرات والنتائج عبر الإصدارات المدقّقة، الأحدث أولاً.
| الإصدار | التاريخ | النتيجة | عناصر المراجعة | التغيير مقارنةً بالسابقة |
|---|---|---|---|---|
| v6 الأحدث | 9. Juli 2026, 11:33 | لا توجد نتائج مؤكَّدة | 0 | لا تغيير في القدرات |
| v5 | 9. Juli 2026, 11:33 | لا توجد نتائج مؤكَّدة | 0 | لا تغيير في القدرات |
| v4 | 6. Juli 2026, 18:54 | لا توجد نتائج مؤكَّدة | 6 | لا تغيير في القدرات |
| v3 | 6. Juli 2026, 18:54 | لا توجد نتائج مؤكَّدة | 6 | لا تغيير في القدرات |
| v2 | 30. Juni 2026, 06:16 | لا توجد نتائج مؤكَّدة | 1 | لا تغيير في القدرات |
| v1 | 16. Feb. 2026, 08:58 | لا توجد نتائج مؤكَّدة | 0 | الأساس |
9. Juli 2026, 11:33
The static alerts are false positives caused by Markdown backticks, TypeScript examples, Object.keys, and ordinary callback names in documentation. I found no prompt injection, data exfiltration intent, or malicious execution behavior in the cited files. The skill documents local Dify pnpm commands, so users should apply normal review before running project scripts.
عوامل الخطر
⚙️ الأوامر الخارجية (50)
9. Juli 2026, 11:33
The static alerts are false positives caused by Markdown backticks, TypeScript examples, Object.keys, and ordinary callback names in documentation. I found no prompt injection, data exfiltration intent, or malicious execution behavior in the cited files. The skill documents local Dify pnpm commands, so users should apply normal review before running project scripts.
عوامل الخطر
⚙️ الأوامر الخارجية (50)
6. Juli 2026, 18:54
No prompt injection, credential exposure, data exfiltration, or system reconnaissance intent was found in the reviewed skill files. Most static findings are Markdown, TypeScript examples, or file path references; the remaining confirmed findings are legitimate local pnpm command instructions that require user confirmation.
عناصر مراجعة القدرات (6)
هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.
عوامل الخطر
⚙️ الأوامر الخارجية (73)
6. Juli 2026, 18:54
No prompt injection, credential exposure, data exfiltration, or system reconnaissance intent was found in the reviewed skill files. Most static findings are Markdown, TypeScript examples, or file path references; the remaining confirmed findings are legitimate local pnpm command instructions that require user confirmation.
عناصر مراجعة القدرات (6)
هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.
عوامل الخطر
⚙️ الأوامر الخارجية (73)
30. Juni 2026, 06:16
Static analysis reported many high-risk patterns, but review found they are Markdown examples, file names, or ordinary TypeScript identifiers. The only confirmed risk factor is legitimate external command guidance for pnpm scripts, which should be used only in trusted Dify repositories. No prompt injection, credential exfiltration, destructive command, or malicious intent was found.
عناصر مراجعة القدرات (1)
هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.
تم تجاهل الإيجابيات الكاذبة الثابتة (1)
تم تجاهل هذه المطابقات الثابتة بواسطة المراجعة الدلالية أو لأنها طابقت رموزًا خاصة بالمخطط فقط، لذا تُعرض للشفافية لكنها لا تؤثر في درجة الجودة.
عوامل الخطر
⚙️ الأوامر الخارجية (5)
16. Feb. 2026, 08:58
This is a documentation and guidance skill for React component refactoring. Static analyzer flagged 214 potential issues in markdown documentation files, all of which are false positives: backticks in code examples were detected as shell commands, code patterns triggered crypto/blocker alerts, and Object.keys() was flagged as certificate/key files. The skill provides reference documentation only and does not execute any code.