Historial de auditorías
provider-management - 6 auditorías
Versión de auditoría 6
Más reciente Riesgo medioJun 28, 2026, 12:25 PM
Static analysis reported many external command hits, but review shows these are Markdown inline code spans and fenced examples rather than executable scripts. The real risks are semantic: the skill documents command-line handling of API keys and session tokens, and it stores credentials and OAuth tokens under a hidden home-directory path without verifiable encryption.
Problemas de riesgo medio (2)
Problemas de riesgo bajo (3)
Factores de riesgo
⚙️ Comandos externos (7)
📁 Acceso al sistema de archivos (1)
Patrones detectados
Versión de auditoría 5
SeguroJan 16, 2026, 05:32 PM
This skill contains only documentation files (SKILL.md). No executable code exists. All 71 static findings are false positives triggered by markdown documentation syntax misinterpreted as code patterns.
Factores de riesgo
⚙️ Comandos externos (56)
📁 Acceso al sistema de archivos (2)
Versión de auditoría 4
SeguroJan 16, 2026, 05:32 PM
This skill contains only documentation files (SKILL.md). No executable code exists. All 71 static findings are false positives triggered by markdown documentation syntax misinterpreted as code patterns.
Factores de riesgo
⚙️ Comandos externos (56)
📁 Acceso al sistema de archivos (2)
Versión de auditoría 3
SeguroJan 10, 2026, 10:41 AM
Pure documentation-only skill. No code execution, no file system access, no network calls. SKILL.md contains only command documentation for a provider management system.
Versión de auditoría 2
SeguroJan 10, 2026, 10:41 AM
Pure documentation-only skill. No code execution, no file system access, no network calls. SKILL.md contains only command documentation for a provider management system.
Versión de auditoría 1
SeguroJan 10, 2026, 10:41 AM
Pure documentation-only skill. No code execution, no file system access, no network calls. SKILL.md contains only command documentation for a provider management system.