Audit-Verlauf
teach-impeccable - 4 Audits
Versionsvergleich
Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.
| Version | Datum | Ergebnis | Prüfelemente | Änderung ggü. vorheriger |
|---|---|---|---|---|
| v4 Neueste | 6. Juli 2026, 20:47 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v3 | 6. Juli 2026, 20:47 | Keine bestätigten Befunde | 0 | Externe Befehle Dateisystemzugriff |
| v2 | 30. Juni 2026, 10:44 | Keine bestätigten Befunde | 1 | Dateisystemzugriff Externe Befehle |
| v1 | 16. März 2026, 08:32 | Keine bestätigten Befunde | 0 | Ausgangsbasis |
6. Juli 2026, 20:47
The three static findings are false positives caused by inline and fenced markdown backticks in SKILL.md. I found no prompt injection attempt, data exfiltration intent, or executable command path in the reviewed file. The skill does ask the assistant to write design context to local project files, which matches its stated setup purpose.
Risikofaktoren
⚙️ Externe Befehle (3)
6. Juli 2026, 20:47
The three static findings are false positives caused by inline and fenced markdown backticks in SKILL.md. I found no prompt injection attempt, data exfiltration intent, or executable command path in the reviewed file. The skill does ask the assistant to write design context to local project files, which matches its stated setup purpose.
Risikofaktoren
⚙️ Externe Befehle (3)
30. Juni 2026, 10:44
Static external command and weak cryptography findings are false positives from Markdown formatting and ordinary design vocabulary. The only confirmed concern is low-risk filesystem persistence because the skill writes design context to project files and may update an AI config file after asking.
Elemente der Fähigkeitsprüfung (1)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.
Statische falsch positive Treffer ignoriert (2)
Diese statischen Treffer wurden durch semantische Prüfung verworfen oder entsprachen reinen Schema-Tokens; daher werden sie aus Transparenzgründen angezeigt, beeinflussen jedoch nicht die Qualitätsbewertung.
Risikofaktoren
📁 Dateisystemzugriff (2)
16. März 2026, 08:32
All static analysis findings are false positives. The skill is instructional markdown that guides AI to gather design context through codebase exploration and user questions. Markdown backticks were misidentified as shell commands. No cryptographic operations exist. Safe for publication.