Fähigkeiten onboard Audit-Verlauf
📦

Audit-Verlauf

onboard - 4 Audits

Versionsvergleich

Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.

VersionDatumErgebnisPrüfelementeÄnderung ggü. vorheriger
v4 Neueste6. Juli 2026, 20:30 Keine bestätigten Befunde0Keine Änderung der Fähigkeiten
v3 6. Juli 2026, 20:30 Keine bestätigten Befunde0Externe Befehle
v2 30. Juni 2026, 11:34 2 bestätigt0Keine Änderung der Fähigkeiten
v1 16. März 2026, 08:34 Keine bestätigten Befunde0Ausgangsbasis

6. Juli 2026, 20:30

The static findings are false positives caused by Markdown code fences, inline Markdown formatting, and UX guidance in SKILL.md. I found no evidence of shell execution, system reconnaissance, data exfiltration, prompt injection, or malicious intent in the reviewed file.

1
Gescannte Dateien
250
Analysierte Zeilen
1
Prüfelemente
0
Falschmeldungen ignoriert
Geprüft von: codex

6. Juli 2026, 20:30

The static findings are false positives caused by Markdown code fences, inline Markdown formatting, and UX guidance in SKILL.md. I found no evidence of shell execution, system reconnaissance, data exfiltration, prompt injection, or malicious intent in the reviewed file.

1
Gescannte Dateien
250
Analysierte Zeilen
1
Prüfelemente
0
Falschmeldungen ignoriert
Geprüft von: codex

30. Juni 2026, 11:34

Static analysis reported command execution, weak cryptography, browser storage, and reconnaissance patterns. Review found the command, crypto, and reconnaissance hits are markdown or natural-language false positives. LocalStorage appears only as benign onboarding-state guidance, so the skill is safe to publish with a minor privacy caution.

1
Gescannte Dateien
250
Analysierte Zeilen
2
Prüfelemente
2
Falschmeldungen ignoriert

Bestätigte Sicherheitsbedenken (2)

Niedrig
Browser Storage Guidance Stores Only Onboarding State
Verdict: FALSE_POSITIVE for sensitive data exposure. The LocalStorage examples store completion and tooltip-seen flags only. This is not credential storage, but implementers should avoid storing personal data or secrets in browser storage.
The examples use fixed onboarding keys with boolean-like values. There is no evidence of tokens, credentials, profile data, or exfiltration.
Niedrig
System Reconnaissance Finding Is Validation Guidance
Verdict: FALSE_POSITIVE. The reported line asks designers to validate whether a user completed an onboarding task correctly. No evidence found of host enumeration, system probing, or environment discovery.
The matched text is a product onboarding checklist item. It is unrelated to system reconnaissance or local machine inspection.
Statische falsch positive Treffer ignoriert (2)

Diese statischen Treffer wurden durch semantische Prüfung verworfen oder entsprachen reinen Schema-Tokens; daher werden sie aus Transparenzgründen angezeigt, beeinflussen jedoch nicht die Qualitätsbewertung.

Niedrig
Static External Command Findings Are Markdown False Positives
Verdict: FALSE_POSITIVE. The reported backtick execution locations are markdown code fences or inline UI examples, not executable Ruby or shell commands. No evidence found of command execution instructions or user-controlled shell input.
The matched lines are visible as markdown delimiters or inline keyboard and help text. They do not invoke a shell, interpreter, or external process.
Niedrig
Weak Cryptography Findings Are Natural-Language False Positives
Verdict: FALSE_POSITIVE. The weak cryptography detector appears to match text such as design-related wording, headings, and UX guidance. No evidence found of DES, MD5, SHA-1, encryption code, hashing code, or cryptographic configuration.
The skill is a prose design guide and contains no cryptographic API usage. The reported lines are headings or UX instructions.
Geprüft von: codex

16. März 2026, 08:34

Static analysis detected 22 potential security issues, all confirmed as false positives after manual review. The skill file contains only Markdown documentation with code examples demonstrating UX patterns. No executable code or security risks present.

1
Gescannte Dateien
250
Analysierte Zeilen
0
Prüfelemente
0
Falschmeldungen ignoriert
Für dieses abgeschlossene Audit wurden keine bestätigten Sicherheitsbefunde erfasst.
Geprüft von: claude