Habilidades flow-attention-refresh Historial de auditorías
📦

Historial de auditorías

flow-attention-refresh - 8 auditorías

Comparación de versiones

Cambios de capacidades y hallazgos entre versiones auditadas, primero las más recientes.

VersiónFechaResultadoElementos de revisiónCambio vs anterior
v8 Más reciente6 jul 2026, 12:44 Sin hallazgos confirmados0Sin cambios de capacidad
v7 6 jul 2026, 12:44 Sin hallazgos confirmados0Comandos externos
v6 29 jun 2026, 18:43 Sin hallazgos confirmados0 Comandos externos
v5 17 ene 2026, 02:21 Sin hallazgos confirmados0Sin cambios de capacidad
v4 17 ene 2026, 02:21 Sin hallazgos confirmados0Comandos externos
v3 10 ene 2026, 14:15 Sin hallazgos confirmados0Sin cambios de capacidad
v2 10 ene 2026, 14:15 Sin hallazgos confirmados0Sin cambios de capacidad
v1 10 ene 2026, 14:15 Sin hallazgos confirmados0Base

6 jul 2026, 12:44

All external command findings are false positives from Markdown code fences and inline backticks in SKILL.md. The high-entropy finding is also a false positive; the file is readable documentation with no encoded payload or prompt injection evidence.

1
Archivos escaneados
171
Líneas analizadas
1
Elementos de revisión
0
Falsos positivos ignorados
Auditado por: codex

6 jul 2026, 12:44

All external command findings are false positives from Markdown code fences and inline backticks in SKILL.md. The high-entropy finding is also a false positive; the file is readable documentation with no encoded payload or prompt injection evidence.

1
Archivos escaneados
171
Líneas analizadas
1
Elementos de revisión
0
Falsos positivos ignorados
Auditado por: codex

29 jun 2026, 18:43

Static analysis flagged Markdown backticks as Ruby or shell command execution, but the file contains documentation code fences, YAML-style examples, and diagrams rather than executable code. The weak cryptography and high-entropy alerts also appear to be false positives caused by multilingual front matter and dense non-ASCII documentation. No prompt injection, network access, credential handling, or executable payload was found in the reviewed file.

1
Archivos escaneados
171
Líneas analizadas
0
Elementos de revisión
3
Falsos positivos ignorados
Falsos positivos estáticos ignorados (3)

Estas coincidencias estáticas fueron descartadas por la revisión semántica o coincidieron con tokens solo de esquema, por lo que se muestran por transparencia, pero no afectan la puntuación de calidad.

Bajo
False Positive: Markdown Code Fences Flagged as Command Execution
Verdict: FALSE_POSITIVE. The reported Ruby or shell backtick locations are Markdown fences and workflow examples. They describe reading planning files and focusing on acceptance criteria, but they do not execute commands or interpolate user input.
The evidence is plainly Markdown documentation, including fenced diagrams and YAML-style examples. I found no shell invocation syntax, executable script, or dynamic command construction in these ranges.
Bajo
False Positive: Weak Cryptography Pattern
Verdict: FALSE_POSITIVE. The static alert points to the skill description in front matter. That line contains natural language about preventing goal drift, not a cryptographic algorithm or hashing operation.
The flagged line is a quoted description field and does not contain crypto APIs or algorithm names. The alert has no supporting semantic evidence.
Bajo
False Positive: High Entropy From Multilingual Documentation
Verdict: FALSE_POSITIVE. The high-entropy alert appears related to Chinese text and structured Markdown, not binary, encrypted, or obfuscated content. The file is readable prose throughout.
Manual review shows legible front matter, headings, tables, and workflow instructions. I found no encoded payload, packed binary data, or obfuscated script.
No se registraron hallazgos de seguridad confirmados en esta auditoría completada.
Auditado por: codex

17 ene 2026, 02:21

This is a pure documentation skill with zero attack surface. All 35 static findings are false positives: backticks flagged as shell execution are markdown code delimiters; cryptographic algorithm flags are misidentified Chinese characters and text; high entropy flag is normal documentation text. The skill defines when to read local project files (BRAINSTORM.md, TASKS.md, ERROR_LOG.md) and contains no executable code, network calls, command execution, or file writing.

2
Archivos escaneados
343
Líneas analizadas
1
Elementos de revisión
0
Falsos positivos ignorados
Auditado por: claude

17 ene 2026, 02:21

This is a pure documentation skill with zero attack surface. All 35 static findings are false positives: backticks flagged as shell execution are markdown code delimiters; cryptographic algorithm flags are misidentified Chinese characters and text; high entropy flag is normal documentation text. The skill defines when to read local project files (BRAINSTORM.md, TASKS.md, ERROR_LOG.md) and contains no executable code, network calls, command execution, or file writing.

2
Archivos escaneados
343
Líneas analizadas
1
Elementos de revisión
0
Falsos positivos ignorados
Auditado por: claude

10 ene 2026, 14:15

This skill is pure documentation with no executable code. It defines a protocol for reading local project documents (BRAINSTORM.md, TASKS.md, ERROR_LOG.md) at specific workflow checkpoints. No network calls, no file writing, no command execution, no environment variable access. This is a prompt-based guidance skill with zero attack surface.

1
Archivos escaneados
170
Líneas analizadas
0
Elementos de revisión
0
Falsos positivos ignorados
No se registraron hallazgos de seguridad confirmados en esta auditoría completada.
Auditado por: claude

10 ene 2026, 14:15

This skill is pure documentation with no executable code. It defines a protocol for reading local project documents (BRAINSTORM.md, TASKS.md, ERROR_LOG.md) at specific workflow checkpoints. No network calls, no file writing, no command execution, no environment variable access. This is a prompt-based guidance skill with zero attack surface.

1
Archivos escaneados
170
Líneas analizadas
0
Elementos de revisión
0
Falsos positivos ignorados
No se registraron hallazgos de seguridad confirmados en esta auditoría completada.
Auditado por: claude

10 ene 2026, 14:15

This skill is pure documentation with no executable code. It defines a protocol for reading local project documents (BRAINSTORM.md, TASKS.md, ERROR_LOG.md) at specific workflow checkpoints. No network calls, no file writing, no command execution, no environment variable access. This is a prompt-based guidance skill with zero attack surface.

1
Archivos escaneados
170
Líneas analizadas
0
Elementos de revisión
0
Falsos positivos ignorados
No se registraron hallazgos de seguridad confirmados en esta auditoría completada.
Auditado por: claude