📦

Audit-Verlauf

teach-impeccable - 4 Audits

Versionsvergleich

Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.

VersionDatumErgebnisPrüfelementeÄnderung ggü. vorheriger
v4 Neueste6. Juli 2026, 20:47 Keine bestätigten Befunde0Keine Änderung der Fähigkeiten
v3 6. Juli 2026, 20:47 Keine bestätigten Befunde0Externe Befehle Dateisystemzugriff
v2 30. Juni 2026, 10:44 Keine bestätigten Befunde1Dateisystemzugriff Externe Befehle
v1 16. März 2026, 08:32 Keine bestätigten Befunde0Ausgangsbasis

6. Juli 2026, 20:47

The three static findings are false positives caused by inline and fenced markdown backticks in SKILL.md. I found no prompt injection attempt, data exfiltration intent, or executable command path in the reviewed file. The skill does ask the assistant to write design context to local project files, which matches its stated setup purpose.

1
Gescannte Dateien
72
Analysierte Zeilen
1
Prüfelemente
0
Falschmeldungen ignoriert

Risikofaktoren

Geprüft von: codex

6. Juli 2026, 20:47

The three static findings are false positives caused by inline and fenced markdown backticks in SKILL.md. I found no prompt injection attempt, data exfiltration intent, or executable command path in the reviewed file. The skill does ask the assistant to write design context to local project files, which matches its stated setup purpose.

1
Gescannte Dateien
72
Analysierte Zeilen
1
Prüfelemente
0
Falschmeldungen ignoriert

Risikofaktoren

Geprüft von: codex

30. Juni 2026, 10:44

Static external command and weak cryptography findings are false positives from Markdown formatting and ordinary design vocabulary. The only confirmed concern is low-risk filesystem persistence because the skill writes design context to project files and may update an AI config file after asking.

1
Gescannte Dateien
72
Analysierte Zeilen
2
Prüfelemente
2
Falschmeldungen ignoriert
Elemente der Fähigkeitsprüfung (1)

Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.

Niedrig
Persistent Project File Modification
The skill instructs the agent to write a Design Context section to .impeccable.md and optionally update an AI config file. This is disclosed behavior and requires confirmation for the config update, but it persists guidance into future sessions.
The file-write instructions are explicit and in scope for the skill. I found no evidence of hidden exfiltration, command execution, or malicious persistence.
Statische falsch positive Treffer ignoriert (2)

Diese statischen Treffer wurden durch semantische Prüfung verworfen oder entsprachen reinen Schema-Tokens; daher werden sie aus Transparenzgründen angezeigt, beeinflussen jedoch nicht die Qualitätsbewertung.

Niedrig
Static External Command Findings Are False Positives
The static analyzer flagged Ruby or shell backtick execution, but the referenced lines are inline Markdown and a fenced Markdown template. They do not execute commands or define executable code.
The exact lines contain Markdown syntax and placeholder text only. There is no shell command, Ruby code, script file, or user-controlled execution path.
Niedrig
Static Weak Cryptography Findings Are False Positives
The weak cryptography detections appear to match ordinary words in the skill description and design guidance. I found no hashing, encryption, signature handling, or cryptographic algorithm use in SKILL.md.
Review of SKILL.md shows no cryptographic operations. The repeated matches are not connected to any security-sensitive algorithm or data flow.

Risikofaktoren

📁 Dateisystemzugriff (2)
Geprüft von: codex

16. März 2026, 08:32

All static analysis findings are false positives. The skill is instructional markdown that guides AI to gather design context through codebase exploration and user questions. Markdown backticks were misidentified as shell commands. No cryptographic operations exist. Safe for publication.

1
Gescannte Dateien
72
Analysierte Zeilen
1
Prüfelemente
0
Falschmeldungen ignoriert

Risikofaktoren

Geprüft von: claude