Audit-Verlauf
skill-creator - 9 Audits
Versionsvergleich
Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.
| Version | Datum | Ergebnis | Prüfelemente | Änderung ggü. vorheriger |
|---|---|---|---|---|
| v9 Neueste | 17. Aug. 2026, 05:39 | 1 bestätigt | 0 | Netzwerkzugriff |
| v8 | 9. Juli 2026, 11:33 | 2 bestätigt | 2 | Keine Änderung der Fähigkeiten |
| v7 | 9. Juli 2026, 11:33 | 2 bestätigt | 2 | Keine Änderung der Fähigkeiten |
| v6 | 7. Juli 2026, 05:39 | Keine bestätigten Befunde | 2 | Externe Befehle Enthält Skripte |
| v5 | 30. Juni 2026, 20:05 | Keine bestätigten Befunde | 0 | Enthält Skripte NetzwerkzugriffExterne Befehle |
| v4 | 17. Jan. 2026, 08:05 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v3 | 17. Jan. 2026, 08:05 | Keine bestätigten Befunde | 0 | NetzwerkzugriffExterne BefehleDateisystemzugriff |
| v2 | 6. Jan. 2026, 01:17 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v1 | 6. Jan. 2026, 01:17 | Keine bestätigten Befunde | 0 | Ausgangsbasis |
17. Aug. 2026, 05:39
All 70 static findings are false positives caused by SVG decimals, documentation examples, error text, or Markdown formatting. One medium issue remains because the metadata generator follows symbolic links when overwriting agents/openai.yaml.
Bestätigte Sicherheitsbedenken (1)
Risikofaktoren
🌐 Netzwerkzugriff (3)
⚙️ Externe Befehle (46)
📁 Dateisystemzugriff (4)
9. Juli 2026, 11:33
Most static alerts are false positives caused by Markdown backticks, example text, validation messages, or normal key set checks. The confirmed static issue is expected archive creation during packaging. Two low contextual risks concern broad packaging and user-selected output paths, with no prompt injection, credential access, network use, or hidden command execution found.
Bestätigte Sicherheitsbedenken (2)
Elemente der Fähigkeitsprüfung (2)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.
Risikofaktoren
⚙️ Externe Befehle (46)
📁 Dateisystemzugriff (2)
9. Juli 2026, 11:33
Most static alerts are false positives caused by Markdown backticks, example text, validation messages, or normal key set checks. The confirmed static issue is expected archive creation during packaging. Two low contextual risks concern broad packaging and user-selected output paths, with no prompt injection, credential access, network use, or hidden command execution found.
Bestätigte Sicherheitsbedenken (2)
Elemente der Fähigkeitsprüfung (2)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.
Risikofaktoren
⚙️ Externe Befehle (46)
📁 Dateisystemzugriff (2)
7. Juli 2026, 05:39
Static analysis produced many pattern matches, but most are false positives from Markdown backticks, template text, and validation variable names. The confirmed behavior is local archive creation in package_skill.py; no prompt injection, network access, credential handling, or destructive behavior was found.
Elemente der Fähigkeitsprüfung (2)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.
Risikofaktoren
⚙️ Externe Befehle (46)
📁 Dateisystemzugriff (2)
30. Juni 2026, 20:05
This official skill provides guidance and local helper scripts for creating, validating, and packaging Codex skills. Static analysis found local file creation, file reading, and zip packaging behavior, but no network access, credential access, prompt injection, or command execution patterns.
Risikofaktoren
⚡ Enthält Skripte (3)
📁 Dateisystemzugriff (3)
17. Jan. 2026, 08:05
Official OpenAI Codex sample skill providing guidance for skill creation. Contains three Python utility scripts for initializing, validating, and packaging skills. All scripts use only standard library, perform filesystem operations only on user-specified paths, and have no network access or external command execution.
Risikofaktoren
🌐 Netzwerkzugriff (2)
⚙️ Externe Befehle (63)
📁 Dateisystemzugriff (3)
17. Jan. 2026, 08:05
Official OpenAI Codex sample skill providing guidance for skill creation. Contains three Python utility scripts for initializing, validating, and packaging skills. All scripts use only standard library, perform filesystem operations only on user-specified paths, and have no network access or external command execution.
Risikofaktoren
🌐 Netzwerkzugriff (2)
⚙️ Externe Befehle (63)
📁 Dateisystemzugriff (3)
6. Jan. 2026, 01:17
Official OpenAI Codex sample skill with safe, well-structured Python scripts for skill initialization, validation, and packaging. No network access, no external commands, no sensitive filesystem operations.
6. Jan. 2026, 01:17
Official OpenAI Codex sample skill with safe, well-structured Python scripts for skill initialization, validation, and packaging. No network access, no external commands, no sensitive filesystem operations.