Habilidades allra-api-design Historial de auditorías
📦

Historial de auditorías

allra-api-design - 6 auditorías

Versión de auditoría 6

Más reciente Seguro

Jun 28, 2026, 09:23 AM

Static analysis reported external command, weak cryptography, and reconnaissance patterns in SKILL.md. Manual review found these are false positives from Markdown code fences, inline examples, and descriptive text. No executable scripts, network access, filesystem access, prompt injection, or malicious intent were found.

1
Archivos escaneados
269
Líneas analizadas
3
hallazgos
codex
Auditado por
Problemas de riesgo bajo (3)
False Positive: Markdown Backtick Examples
FALSE_POSITIVE. The external command detections are Markdown code fences and inline formatting for package trees, DTO names, Java examples, JSON examples, and checklist text. They are documentation examples, not shell execution instructions or runnable skill scripts.
False Positive: Weak Cryptography Match
FALSE_POSITIVE. The weak cryptography detections at the front matter are text matches in the skill name and description. They do not define or recommend DES, MD5, SHA1, or any other weak algorithm.
False Positive: REST Controller Examples
FALSE_POSITIVE. The system reconnaissance detections are Spring controller examples using request bodies and path variables. They describe API design conventions and do not collect host, user, network, or environment information.

Versión de auditoría 5

Seguro

Jan 16, 2026, 03:11 PM

Pure documentation skill containing only API design guidelines. Static scanner produced false positives: 36 'weak cryptographic algorithm' flags are Java 'record' class definitions; 31 'shell backtick execution' flags are markdown code formatting; 5 'system reconnaissance' flags are Spring @PathVariable annotations. No executable code, network access, file system access, or external commands.

2
Archivos escaneados
446
Líneas analizadas
1
hallazgos
claude
Auditado por
No se encontraron problemas de seguridad

Versión de auditoría 4

Seguro

Jan 16, 2026, 03:11 PM

Pure documentation skill containing only API design guidelines. Static scanner produced false positives: 36 'weak cryptographic algorithm' flags are Java 'record' class definitions; 31 'shell backtick execution' flags are markdown code formatting; 5 'system reconnaissance' flags are Spring @PathVariable annotations. No executable code, network access, file system access, or external commands.

2
Archivos escaneados
446
Líneas analizadas
1
hallazgos
claude
Auditado por
No se encontraron problemas de seguridad

Versión de auditoría 3

Seguro

Jan 10, 2026, 10:16 AM

Pure prompt-based documentation skill containing only API design guidelines. No executable code, no network access, no file system access, no external commands. This skill provides documentation for Java Spring Boot developers and presents no security risk.

1
Archivos escaneados
269
Líneas analizadas
0
hallazgos
claude
Auditado por
No se encontraron problemas de seguridad

Versión de auditoría 2

Seguro

Jan 10, 2026, 10:16 AM

Pure prompt-based documentation skill containing only API design guidelines. No executable code, no network access, no file system access, no external commands. This skill provides documentation for Java Spring Boot developers and presents no security risk.

1
Archivos escaneados
269
Líneas analizadas
0
hallazgos
claude
Auditado por
No se encontraron problemas de seguridad

Versión de auditoría 1

Seguro

Jan 10, 2026, 10:16 AM

Pure prompt-based documentation skill containing only API design guidelines. No executable code, no network access, no file system access, no external commands. This skill provides documentation for Java Spring Boot developers and presents no security risk.

1
Archivos escaneados
269
Líneas analizadas
0
hallazgos
claude
Auditado por
No se encontraron problemas de seguridad