Historial de auditorías
github-project-management - 8 auditorías
Comparación de versiones
Cambios de capacidades y hallazgos entre versiones auditadas, primero las más recientes.
| Versión | Fecha | Resultado | Elementos de revisión | Cambio vs anterior |
|---|---|---|---|---|
| v8 Más reciente | 5 jul 2026, 13:20 | 3 confirmado | 0 | Sin cambios de capacidad |
| v7 | 5 jul 2026, 13:20 | 3 confirmado | 0 | Sin cambios de capacidad |
| v6 | 29 jun 2026, 19:06 | Sin hallazgos confirmados | 4 | Sin cambios de capacidad |
| v5 | 17 ene 2026, 03:32 | Sin hallazgos confirmados | 0 | Sin cambios de capacidad |
| v4 | 17 ene 2026, 03:32 | Sin hallazgos confirmados | 0 | Acceso a redAcceso al sistema de archivosComandos externos |
| v3 | 10 ene 2026, 13:22 | Sin hallazgos confirmados | 0 | Sin cambios de capacidad |
| v2 | 10 ene 2026, 13:22 | Sin hallazgos confirmados | 0 | Sin cambios de capacidad |
| v1 | 10 ene 2026, 13:22 | Sin hallazgos confirmados | 0 | Base |
5 jul 2026, 13:20
Most static findings are false positives caused by markdown fences, inline code, and visible bash examples in SKILL.md. The skill shows legitimate GitHub project-management intent, but it carries medium contextual risk from unpinned third-party npx commands, automated GitHub mutations, and external webhook sync.
Preocupaciones de seguridad confirmadas (3)
Factores de riesgo
⚙️ Comandos externos (139)
🌐 Acceso a red (7)
📁 Acceso al sistema de archivos (1)
5 jul 2026, 13:20
Most static findings are false positives caused by markdown fences, inline code, and visible bash examples in SKILL.md. The skill shows legitimate GitHub project-management intent, but it carries medium contextual risk from unpinned third-party npx commands, automated GitHub mutations, and external webhook sync.
Preocupaciones de seguridad confirmadas (3)
Factores de riesgo
⚙️ Comandos externos (139)
🌐 Acceso a red (7)
📁 Acceso al sistema de archivos (1)
29 jun 2026, 19:06
Static analysis reported many command execution and high-risk keyword patterns in SKILL.md. Review found no prompt injection, malware intent, or real weak cryptography, but confirmed extensive GitHub CLI, npx, and MCP examples that can mutate repositories and project boards. Publish with a clear warning that users must review commands and permissions before execution.
Elementos de revisión de capacidades (4)
Estas son capacidades locales reales que pueden esperarse para esta habilidad, por lo que requieren revisión, pero no se cuentan como comportamiento malicioso confirmado.
Falsos positivos estáticos ignorados (1)
Estas coincidencias estáticas fueron descartadas por la revisión semántica o coincidieron con tokens solo de esquema, por lo que se muestran por transparencia, pero no afectan la puntuación de calidad.
Factores de riesgo
⚙️ Comandos externos (6)
🌐 Acceso a red (4)
📁 Acceso al sistema de archivos (1)
Patrones detectados
17 ene 2026, 03:32
Documentation-only skill containing markdown guidance for GitHub project management workflows. Static findings are false positives triggered by documentation patterns showing example shell commands. No executable code, no network operations, no file system access. External tools (gh CLI, ruv-swarm) are invoked by the user, not by this skill.
Factores de riesgo
🌐 Acceso a red (7)
📁 Acceso al sistema de archivos (1)
⚙️ Comandos externos (139)
17 ene 2026, 03:32
Documentation-only skill containing markdown guidance for GitHub project management workflows. Static findings are false positives triggered by documentation patterns showing example shell commands. No executable code, no network operations, no file system access. External tools (gh CLI, ruv-swarm) are invoked by the user, not by this skill.
Factores de riesgo
🌐 Acceso a red (7)
📁 Acceso al sistema de archivos (1)
⚙️ Comandos externos (139)
10 ene 2026, 13:22
Pure documentation skill containing only markdown guidance for GitHub project management workflows. No executable code, no network operations, no file system access, no environment variable reading. External tools (gh CLI, ruv-swarm) are invoked by the user, not by this skill.
10 ene 2026, 13:22
Pure documentation skill containing only markdown guidance for GitHub project management workflows. No executable code, no network operations, no file system access, no environment variable reading. External tools (gh CLI, ruv-swarm) are invoked by the user, not by this skill.
10 ene 2026, 13:22
Pure documentation skill containing only markdown guidance for GitHub project management workflows. No executable code, no network operations, no file system access, no environment variable reading. External tools (gh CLI, ruv-swarm) are invoked by the user, not by this skill.