Historial de auditorías
pitfalls-blockchain - 7 auditorías
Versión de auditoría 7
Más reciente Riesgo bajoJun 28, 2026, 12:59 PM
Static analysis reported command execution, network, environment, wallet, weak crypto, and combined-risk patterns. Review found these are Markdown and TypeScript examples, not executable skill code, with no evidence of prompt injection or malicious intent. The only residual concerns are documentation examples that mention RPC endpoints and environment variables.
Problemas de riesgo bajo (5)
Factores de riesgo
🌐 Acceso a red (3)
🔑 Variables de entorno (2)
Versión de auditoría 6
SeguroJan 21, 2026, 02:52 PM
Static scanner flagged 41 patterns but all are false positives. The skill is pure documentation with TypeScript code examples for blockchain best practices. Findings include misidentified markdown code blocks as shell execution, environment variable examples as credential access, and example RPC URLs as hardcoded endpoints. No executable code, no network calls, no credential exfiltration.
Factores de riesgo
🌐 Acceso a red (1)
⚙️ Comandos externos (6)
🔑 Variables de entorno (2)
Versión de auditoría 5
Riesgo medioJan 16, 2026, 06:11 PM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Factores de riesgo
🌐 Acceso a red (3)
🔑 Variables de entorno (4)
Patrones detectados
Versión de auditoría 4
Riesgo medioJan 16, 2026, 06:11 PM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Factores de riesgo
🌐 Acceso a red (3)
🔑 Variables de entorno (4)
Patrones detectados
Versión de auditoría 3
SeguroJan 10, 2026, 11:18 AM
This is a pure prompt-based skill containing only documentation and code examples. No executable code, network calls, file system access, or environment variable reading. The process.env references in examples are documentation only.
Versión de auditoría 2
SeguroJan 10, 2026, 11:18 AM
This is a pure prompt-based skill containing only documentation and code examples. No executable code, network calls, file system access, or environment variable reading. The process.env references in examples are documentation only.
Versión de auditoría 1
SeguroJan 10, 2026, 11:18 AM
This is a pure prompt-based skill containing only documentation and code examples. No executable code, network calls, file system access, or environment variable reading. The process.env references in examples are documentation only.