Audit-Verlauf
onboard - 4 Audits
Versionsvergleich
Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.
| Version | Datum | Ergebnis | Prüfelemente | Änderung ggü. vorheriger |
|---|---|---|---|---|
| v4 Neueste | 6. Juli 2026, 20:30 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v3 | 6. Juli 2026, 20:30 | Keine bestätigten Befunde | 0 | Externe Befehle |
| v2 | 30. Juni 2026, 11:34 | 2 bestätigt | 0 | Keine Änderung der Fähigkeiten |
| v1 | 16. März 2026, 08:34 | Keine bestätigten Befunde | 0 | Ausgangsbasis |
6. Juli 2026, 20:30
The static findings are false positives caused by Markdown code fences, inline Markdown formatting, and UX guidance in SKILL.md. I found no evidence of shell execution, system reconnaissance, data exfiltration, prompt injection, or malicious intent in the reviewed file.
Risikofaktoren
⚙️ Externe Befehle (5)
6. Juli 2026, 20:30
The static findings are false positives caused by Markdown code fences, inline Markdown formatting, and UX guidance in SKILL.md. I found no evidence of shell execution, system reconnaissance, data exfiltration, prompt injection, or malicious intent in the reviewed file.
Risikofaktoren
⚙️ Externe Befehle (5)
30. Juni 2026, 11:34
Static analysis reported command execution, weak cryptography, browser storage, and reconnaissance patterns. Review found the command, crypto, and reconnaissance hits are markdown or natural-language false positives. LocalStorage appears only as benign onboarding-state guidance, so the skill is safe to publish with a minor privacy caution.
Bestätigte Sicherheitsbedenken (2)
Statische falsch positive Treffer ignoriert (2)
Diese statischen Treffer wurden durch semantische Prüfung verworfen oder entsprachen reinen Schema-Tokens; daher werden sie aus Transparenzgründen angezeigt, beeinflussen jedoch nicht die Qualitätsbewertung.
16. März 2026, 08:34
Static analysis detected 22 potential security issues, all confirmed as false positives after manual review. The skill file contains only Markdown documentation with code examples demonstrating UX patterns. No executable code or security risks present.