📦

Audit-Verlauf

data-engineer - 4 Audits

Versionsvergleich

Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.

VersionDatumErgebnisPrüfelementeÄnderung ggü. vorheriger
v4 Neueste23. Juli 2026, 23:28 1 bestätigt0Keine Änderung der Fähigkeiten
v3 15. Juli 2026, 15:03 2 bestätigt0Keine Änderung der Fähigkeiten
v2 15. Juli 2026, 15:03 2 bestätigt0Keine Änderung der Fähigkeiten
v1 15. Juli 2026, 15:03 2 bestätigt0Ausgangsbasis

23. Juli 2026, 23:28

All 42 backtick detections are Markdown fences or inline code, not shell execution. Eight reconnaissance matches are schema identifiers, and multilingual diagrams explain the entropy alert. Destructive delete and overwrite examples still lack confirmation, backup, and environment safeguards.

1
Gescannte Dateien
1,058
Analysierte Zeilen
2
Prüfelemente
0
Falschmeldungen ignoriert

Bestätigte Sicherheitsbedenken (1)

Mittel
Destructive Data Operations Lack Guardrails
The command reference shows an ALTER TABLE DELETE, and the PySpark template uses overwrite mode. Neither example requires confirmation, backup verification, or a dry run.
Both destructive operations appear directly in reusable examples, with no adjacent safety gate. The placeholder targets reduce immediate impact but not reuse risk.
Geprüft von: codex

15. Juli 2026, 15:03

All 51 static findings are false positives caused by Markdown formatting, SQL identifiers, multilingual text, and documentation examples. No prompt injection, hidden executable payload, or obfuscation was found. Operational examples can still delete or overwrite data without explicit confirmation safeguards.

1
Gescannte Dateien
1,058
Analysierte Zeilen
3
Prüfelemente
0
Falschmeldungen ignoriert

Bestätigte Sicherheitsbedenken (2)

Mittel
Destructive Operations Lack Confirmation Safeguards
The command reference includes a database delete, and the PySpark template uses overwrite mode. The skill does not require confirmation, backups, or dry runs before these actions.
Both destructive patterns are explicit examples, and surrounding guidance directs the agent to deploy and run pipelines. Risk depends on access to live systems.
Niedrig
Inline Credential Pattern in JDBC Example
The JDBC example places username and password values directly in pipeline code. Although placeholders, this pattern can encourage users to embed real credentials.
The username and password options are visibly embedded in the example. They are placeholders, so no actual secret exposure is present.

Risikofaktoren

⚙️ Externe Befehle (1)
Geprüft von: codex

15. Juli 2026, 15:03

All 51 static findings are false positives caused by Markdown formatting, SQL identifiers, multilingual text, and documentation examples. No prompt injection, hidden executable payload, or obfuscation was found. Operational examples can still delete or overwrite data without explicit confirmation safeguards.

1
Gescannte Dateien
1,058
Analysierte Zeilen
3
Prüfelemente
0
Falschmeldungen ignoriert

Bestätigte Sicherheitsbedenken (2)

Mittel
Destructive Operations Lack Confirmation Safeguards
The command reference includes a database delete, and the PySpark template uses overwrite mode. The skill does not require confirmation, backups, or dry runs before these actions.
Both destructive patterns are explicit examples, and surrounding guidance directs the agent to deploy and run pipelines. Risk depends on access to live systems.
Niedrig
Inline Credential Pattern in JDBC Example
The JDBC example places username and password values directly in pipeline code. Although placeholders, this pattern can encourage users to embed real credentials.
The username and password options are visibly embedded in the example. They are placeholders, so no actual secret exposure is present.

Risikofaktoren

⚙️ Externe Befehle (1)
Geprüft von: codex

15. Juli 2026, 15:03

All 51 static findings are false positives caused by Markdown formatting, SQL identifiers, multilingual text, and documentation examples. No prompt injection, hidden executable payload, or obfuscation was found. Operational examples can still delete or overwrite data without explicit confirmation safeguards.

1
Gescannte Dateien
1,058
Analysierte Zeilen
3
Prüfelemente
0
Falschmeldungen ignoriert

Bestätigte Sicherheitsbedenken (2)

Mittel
Destructive Operations Lack Confirmation Safeguards
The command reference includes a database delete, and the PySpark template uses overwrite mode. The skill does not require confirmation, backups, or dry runs before these actions.
Both destructive patterns are explicit examples, and surrounding guidance directs the agent to deploy and run pipelines. Risk depends on access to live systems.
Niedrig
Inline Credential Pattern in JDBC Example
The JDBC example places username and password values directly in pipeline code. Although placeholders, this pattern can encourage users to embed real credentials.
The username and password options are visibly embedded in the example. They are placeholders, so no actual secret exposure is present.

Risikofaktoren

⚙️ Externe Befehle (1)
Geprüft von: codex