Habilidades github-project-management Historial de auditorías
📦

Historial de auditorías

github-project-management - 8 auditorías

Comparación de versiones

Cambios de capacidades y hallazgos entre versiones auditadas, primero las más recientes.

VersiónFechaResultadoElementos de revisiónCambio vs anterior
v8 Más reciente5 jul 2026, 13:20 3 confirmado0Sin cambios de capacidad
v7 5 jul 2026, 13:20 3 confirmado0Sin cambios de capacidad
v6 29 jun 2026, 19:06 Sin hallazgos confirmados4Sin cambios de capacidad
v5 17 ene 2026, 03:32 Sin hallazgos confirmados0Sin cambios de capacidad
v4 17 ene 2026, 03:32 Sin hallazgos confirmados0Acceso a redAcceso al sistema de archivosComandos externos
v3 10 ene 2026, 13:22 Sin hallazgos confirmados0Sin cambios de capacidad
v2 10 ene 2026, 13:22 Sin hallazgos confirmados0Sin cambios de capacidad
v1 10 ene 2026, 13:22 Sin hallazgos confirmados0Base

5 jul 2026, 13:20

Most static findings are false positives caused by markdown fences, inline code, and visible bash examples in SKILL.md. The skill shows legitimate GitHub project-management intent, but it carries medium contextual risk from unpinned third-party npx commands, automated GitHub mutations, and external webhook sync.

1
Archivos escaneados
1,278
Líneas analizadas
6
Elementos de revisión
0
Falsos positivos ignorados

Preocupaciones de seguridad confirmadas (3)

Medio
Unpinned Third-Party CLI Execution
The skill tells users to run npx claude-flow@alpha and many npx ruv-swarm commands. These commands execute third-party package code in a repository context without pinning a stable version or documenting an integrity check.
The npx commands are explicit and frequent, and they would run external package code if executed. No hidden malware intent was found, so the severity is medium rather than high.
Medio
Automated GitHub State Changes Without Confirmation Gates
Several workflows can close duplicate or stale issues, auto-move project cards, and archive completed board items. These are legitimate project operations, but they can cause unwanted repository state changes without a required dry run or approval step.
The cited lines directly show close, auto-management, and archive behavior. The risk is business-logic impact from documented automation, not covert destructive behavior.
Medio
External Webhook Sync May Expose Project Metadata
The real-time board sync example sends updates to an external webhook endpoint. If users configure an untrusted endpoint, private issue, board, or milestone metadata could leave the repository boundary.
The webhook is a placeholder and the skill mentions webhook security, but the workflow still encourages external sync. The data exposure depends on the endpoint a user configures.

Factores de riesgo

⚙️ Comandos externos (139)
SKILL.md:45-54 SKILL.md:54-58 SKILL.md:58-67 SKILL.md:67-80 SKILL.md:80-92 SKILL.md:104-115 SKILL.md:115-119 SKILL.md:119-135 SKILL.md:135-144 SKILL.md:144-164 SKILL.md:164-170 SKILL.md:170-177 SKILL.md:177-186 SKILL.md:186-207 SKILL.md:207-211 SKILL.md:211-224 SKILL.md:224-233 SKILL.md:233-264 SKILL.md:264-268 SKILL.md:268-307 SKILL.md:307-316 SKILL.md:316-353 SKILL.md:353-364 SKILL.md:364-380 SKILL.md:380-384 SKILL.md:384-427 SKILL.md:427-436 SKILL.md:436-453 SKILL.md:453-457 SKILL.md:457-472 SKILL.md:472-481 SKILL.md:481-487 SKILL.md:487-491 SKILL.md:491-499 SKILL.md:499-503 SKILL.md:503-509 SKILL.md:509-518 SKILL.md:518-544 SKILL.md:544-548 SKILL.md:548-573 SKILL.md:573-584 SKILL.md:584-598 SKILL.md:598-602 SKILL.md:602-609 SKILL.md:609-613 SKILL.md:613-622 SKILL.md:622-631 SKILL.md:631-650 SKILL.md:650-654 SKILL.md:654-667 SKILL.md:667-671 SKILL.md:671-688 SKILL.md:688-697 SKILL.md:697-704 SKILL.md:704-715 SKILL.md:715-730 SKILL.md:730-739 SKILL.md:739-745 SKILL.md:745-749 SKILL.md:749-755 SKILL.md:755-764 SKILL.md:764-770 SKILL.md:770-779 SKILL.md:779-786 SKILL.md:786-790 SKILL.md:790-797 SKILL.md:797-801 SKILL.md:801-808 SKILL.md:808-818 SKILL.md:818-857 SKILL.md:857-861 SKILL.md:861-896 SKILL.md:896-900 SKILL.md:900-940 SKILL.md:940-944 SKILL.md:944-970 SKILL.md:970-978 SKILL.md:978-996 SKILL.md:996-1000 SKILL.md:1000-1009 SKILL.md:1009-1017 SKILL.md:1017-1024 SKILL.md:1024-1028 SKILL.md:1028-1035 SKILL.md:1035-1039 SKILL.md:1039-1046 SKILL.md:1046-1094 SKILL.md:1094-1100 SKILL.md:1100-1104 SKILL.md:1104-1111 SKILL.md:1111-1115 SKILL.md:1115-1122 SKILL.md:1122-1150 SKILL.md:1150-1155 SKILL.md:1155-1159 SKILL.md:1159-1164 SKILL.md:1164-1182 SKILL.md:1182-1183 SKILL.md:1183-1184 SKILL.md:1184-1185 SKILL.md:1185-1193 SKILL.md:1193-1237 SKILL.md:1237-1243 SKILL.md:1243-1262 SKILL.md:60-61 SKILL.md:146 SKILL.md:155 SKILL.md:235 SKILL.md:238-241 SKILL.md:244 SKILL.md:254 SKILL.md:255 SKILL.md:270 SKILL.md:273 SKILL.md:276-277 SKILL.md:283-286 SKILL.md:304 SKILL.md:318 SKILL.md:319-320 SKILL.md:325 SKILL.md:328-330 SKILL.md:349 SKILL.md:366-367 SKILL.md:459 SKILL.md:633 SKILL.md:636 SKILL.md:638 SKILL.md:1197-1213 SKILL.md:1217 SKILL.md:1224 SKILL.md:58-67 SKILL.md:144-164 SKILL.md:233-264 SKILL.md:268-307 SKILL.md:316-353 SKILL.md:364-380 SKILL.md:457-472 SKILL.md:631-650 SKILL.md:1193-1237
🌐 Acceso a red (7)
📁 Acceso al sistema de archivos (1)
Auditado por: codex

5 jul 2026, 13:20

Most static findings are false positives caused by markdown fences, inline code, and visible bash examples in SKILL.md. The skill shows legitimate GitHub project-management intent, but it carries medium contextual risk from unpinned third-party npx commands, automated GitHub mutations, and external webhook sync.

1
Archivos escaneados
1,278
Líneas analizadas
6
Elementos de revisión
0
Falsos positivos ignorados

Preocupaciones de seguridad confirmadas (3)

Medio
Unpinned Third-Party CLI Execution
The skill tells users to run npx claude-flow@alpha and many npx ruv-swarm commands. These commands execute third-party package code in a repository context without pinning a stable version or documenting an integrity check.
The npx commands are explicit and frequent, and they would run external package code if executed. No hidden malware intent was found, so the severity is medium rather than high.
Medio
Automated GitHub State Changes Without Confirmation Gates
Several workflows can close duplicate or stale issues, auto-move project cards, and archive completed board items. These are legitimate project operations, but they can cause unwanted repository state changes without a required dry run or approval step.
The cited lines directly show close, auto-management, and archive behavior. The risk is business-logic impact from documented automation, not covert destructive behavior.
Medio
External Webhook Sync May Expose Project Metadata
The real-time board sync example sends updates to an external webhook endpoint. If users configure an untrusted endpoint, private issue, board, or milestone metadata could leave the repository boundary.
The webhook is a placeholder and the skill mentions webhook security, but the workflow still encourages external sync. The data exposure depends on the endpoint a user configures.

Factores de riesgo

⚙️ Comandos externos (139)
SKILL.md:45-54 SKILL.md:54-58 SKILL.md:58-67 SKILL.md:67-80 SKILL.md:80-92 SKILL.md:104-115 SKILL.md:115-119 SKILL.md:119-135 SKILL.md:135-144 SKILL.md:144-164 SKILL.md:164-170 SKILL.md:170-177 SKILL.md:177-186 SKILL.md:186-207 SKILL.md:207-211 SKILL.md:211-224 SKILL.md:224-233 SKILL.md:233-264 SKILL.md:264-268 SKILL.md:268-307 SKILL.md:307-316 SKILL.md:316-353 SKILL.md:353-364 SKILL.md:364-380 SKILL.md:380-384 SKILL.md:384-427 SKILL.md:427-436 SKILL.md:436-453 SKILL.md:453-457 SKILL.md:457-472 SKILL.md:472-481 SKILL.md:481-487 SKILL.md:487-491 SKILL.md:491-499 SKILL.md:499-503 SKILL.md:503-509 SKILL.md:509-518 SKILL.md:518-544 SKILL.md:544-548 SKILL.md:548-573 SKILL.md:573-584 SKILL.md:584-598 SKILL.md:598-602 SKILL.md:602-609 SKILL.md:609-613 SKILL.md:613-622 SKILL.md:622-631 SKILL.md:631-650 SKILL.md:650-654 SKILL.md:654-667 SKILL.md:667-671 SKILL.md:671-688 SKILL.md:688-697 SKILL.md:697-704 SKILL.md:704-715 SKILL.md:715-730 SKILL.md:730-739 SKILL.md:739-745 SKILL.md:745-749 SKILL.md:749-755 SKILL.md:755-764 SKILL.md:764-770 SKILL.md:770-779 SKILL.md:779-786 SKILL.md:786-790 SKILL.md:790-797 SKILL.md:797-801 SKILL.md:801-808 SKILL.md:808-818 SKILL.md:818-857 SKILL.md:857-861 SKILL.md:861-896 SKILL.md:896-900 SKILL.md:900-940 SKILL.md:940-944 SKILL.md:944-970 SKILL.md:970-978 SKILL.md:978-996 SKILL.md:996-1000 SKILL.md:1000-1009 SKILL.md:1009-1017 SKILL.md:1017-1024 SKILL.md:1024-1028 SKILL.md:1028-1035 SKILL.md:1035-1039 SKILL.md:1039-1046 SKILL.md:1046-1094 SKILL.md:1094-1100 SKILL.md:1100-1104 SKILL.md:1104-1111 SKILL.md:1111-1115 SKILL.md:1115-1122 SKILL.md:1122-1150 SKILL.md:1150-1155 SKILL.md:1155-1159 SKILL.md:1159-1164 SKILL.md:1164-1182 SKILL.md:1182-1183 SKILL.md:1183-1184 SKILL.md:1184-1185 SKILL.md:1185-1193 SKILL.md:1193-1237 SKILL.md:1237-1243 SKILL.md:1243-1262 SKILL.md:60-61 SKILL.md:146 SKILL.md:155 SKILL.md:235 SKILL.md:238-241 SKILL.md:244 SKILL.md:254 SKILL.md:255 SKILL.md:270 SKILL.md:273 SKILL.md:276-277 SKILL.md:283-286 SKILL.md:304 SKILL.md:318 SKILL.md:319-320 SKILL.md:325 SKILL.md:328-330 SKILL.md:349 SKILL.md:366-367 SKILL.md:459 SKILL.md:633 SKILL.md:636 SKILL.md:638 SKILL.md:1197-1213 SKILL.md:1217 SKILL.md:1224 SKILL.md:58-67 SKILL.md:144-164 SKILL.md:233-264 SKILL.md:268-307 SKILL.md:316-353 SKILL.md:364-380 SKILL.md:457-472 SKILL.md:631-650 SKILL.md:1193-1237
🌐 Acceso a red (7)
📁 Acceso al sistema de archivos (1)
Auditado por: codex

29 jun 2026, 19:06

Static analysis reported many command execution and high-risk keyword patterns in SKILL.md. Review found no prompt injection, malware intent, or real weak cryptography, but confirmed extensive GitHub CLI, npx, and MCP examples that can mutate repositories and project boards. Publish with a clear warning that users must review commands and permissions before execution.

1
Archivos escaneados
1,278
Líneas analizadas
7
Elementos de revisión
1
Falsos positivos ignorados
Elementos de revisión de capacidades (4)

Estas son capacidades locales reales que pueden esperarse para esta habilidad, por lo que requieren revisión, pero no se cuentan como comportamiento malicioso confirmado.

Medio
External Package and Shell Command Execution
The skill contains many Bash examples using gh, jq, command substitution, and npx packages such as claude-flow and ruv-swarm. This is relevant to GitHub automation, but it executes local commands and third-party package code, so users should approve each command and verify package trust.
The referenced lines directly show shell commands and npx execution. Confidence is not higher because these are documented operational examples for the stated GitHub management purpose, not hidden execution code.
Medio
Repository and Project State Mutation
The skill instructs agents to create, edit, comment on, label, close, and add GitHub issues and project items. These actions are legitimate for project management, but mistakes or overbroad permissions could alter production repositories or close active issues.
The commands clearly perform GitHub write operations. The risk is operational rather than malicious because the behavior matches the skill description.
Bajo
External Webhook Endpoint Example
The board realtime example includes a placeholder HTTPS webhook endpoint. It does not show credential exfiltration, but users should replace it with a trusted endpoint and avoid sending private repository data to unapproved services.
The network endpoint is explicitly present and tied to board synchronization. It appears to be a placeholder domain, so the finding is low severity.
Bajo
Device File Redirection Dismissed
The /dev/null usage suppresses stderr for a GitHub label removal command. This is a common shell pattern and not sensitive filesystem access.
The exact line shows stderr redirection only. There is no file read, write, deletion, or traversal behavior.
Falsos positivos estáticos ignorados (1)

Estas coincidencias estáticas fueron descartadas por la revisión semántica o coincidieron con tokens solo de esquema, por lo que se muestran por transparencia, pero no afectan la puntuación de calidad.

Bajo
Static High-Risk Keyword Findings Dismissed
The static weak-cryptography findings did not correspond to cryptographic operations during review. No evidence found of MD5, SHA-1, custom encryption, credential handling, or obfuscated security logic in SKILL.md.
Targeted review found prose and shell examples rather than cryptographic code at representative flagged locations. The static labels are therefore false positives.

Patrones detectados

npx Execution of Third-Party Automation PackagesAutomated GitHub Write Operations
Auditado por: codex

17 ene 2026, 03:32

Documentation-only skill containing markdown guidance for GitHub project management workflows. Static findings are false positives triggered by documentation patterns showing example shell commands. No executable code, no network operations, no file system access. External tools (gh CLI, ruv-swarm) are invoked by the user, not by this skill.

2
Archivos escaneados
1,458
Líneas analizadas
3
Elementos de revisión
0
Falsos positivos ignorados

Factores de riesgo

🌐 Acceso a red (7)
📁 Acceso al sistema de archivos (1)
⚙️ Comandos externos (139)
SKILL.md:45-54 SKILL.md:54-58 SKILL.md:58-67 SKILL.md:67-80 SKILL.md:80-92 SKILL.md:104-115 SKILL.md:115-119 SKILL.md:119-135 SKILL.md:135-144 SKILL.md:144-164 SKILL.md:164-170 SKILL.md:170-177 SKILL.md:177-186 SKILL.md:186-207 SKILL.md:207-211 SKILL.md:211-224 SKILL.md:224-233 SKILL.md:233-264 SKILL.md:264-268 SKILL.md:268-307 SKILL.md:307-316 SKILL.md:316-353 SKILL.md:353-364 SKILL.md:364-380 SKILL.md:380-384 SKILL.md:384-427 SKILL.md:427-436 SKILL.md:436-453 SKILL.md:453-457 SKILL.md:457-472 SKILL.md:472-481 SKILL.md:481-487 SKILL.md:487-491 SKILL.md:491-499 SKILL.md:499-503 SKILL.md:503-509 SKILL.md:509-518 SKILL.md:518-544 SKILL.md:544-548 SKILL.md:548-573 SKILL.md:573-584 SKILL.md:584-598 SKILL.md:598-602 SKILL.md:602-609 SKILL.md:609-613 SKILL.md:613-622 SKILL.md:622-631 SKILL.md:631-650 SKILL.md:650-654 SKILL.md:654-667 SKILL.md:667-671 SKILL.md:671-688 SKILL.md:688-697 SKILL.md:697-704 SKILL.md:704-715 SKILL.md:715-730 SKILL.md:730-739 SKILL.md:739-745 SKILL.md:745-749 SKILL.md:749-755 SKILL.md:755-764 SKILL.md:764-770 SKILL.md:770-779 SKILL.md:779-786 SKILL.md:786-790 SKILL.md:790-797 SKILL.md:797-801 SKILL.md:801-808 SKILL.md:808-818 SKILL.md:818-857 SKILL.md:857-861 SKILL.md:861-896 SKILL.md:896-900 SKILL.md:900-940 SKILL.md:940-944 SKILL.md:944-970 SKILL.md:970-978 SKILL.md:978-996 SKILL.md:996-1000 SKILL.md:1000-1009 SKILL.md:1009-1017 SKILL.md:1017-1024 SKILL.md:1024-1028 SKILL.md:1028-1035 SKILL.md:1035-1039 SKILL.md:1039-1046 SKILL.md:1046-1094 SKILL.md:1094-1100 SKILL.md:1100-1104 SKILL.md:1104-1111 SKILL.md:1111-1115 SKILL.md:1115-1122 SKILL.md:1122-1150 SKILL.md:1150-1155 SKILL.md:1155-1159 SKILL.md:1159-1164 SKILL.md:1164-1182 SKILL.md:1182-1183 SKILL.md:1183-1184 SKILL.md:1184-1185 SKILL.md:1185-1193 SKILL.md:1193-1237 SKILL.md:1237-1243 SKILL.md:1243-1262 SKILL.md:60-61 SKILL.md:146 SKILL.md:155 SKILL.md:235 SKILL.md:238-241 SKILL.md:244 SKILL.md:254 SKILL.md:255 SKILL.md:270 SKILL.md:273 SKILL.md:276-277 SKILL.md:283-286 SKILL.md:304 SKILL.md:318 SKILL.md:319-320 SKILL.md:325 SKILL.md:328-330 SKILL.md:349 SKILL.md:366-367 SKILL.md:459 SKILL.md:633 SKILL.md:636 SKILL.md:638 SKILL.md:1197-1213 SKILL.md:1217 SKILL.md:1224 SKILL.md:58-67 SKILL.md:144-164 SKILL.md:233-264 SKILL.md:268-307 SKILL.md:316-353 SKILL.md:364-380 SKILL.md:457-472 SKILL.md:631-650 SKILL.md:1193-1237
Auditado por: claude

17 ene 2026, 03:32

Documentation-only skill containing markdown guidance for GitHub project management workflows. Static findings are false positives triggered by documentation patterns showing example shell commands. No executable code, no network operations, no file system access. External tools (gh CLI, ruv-swarm) are invoked by the user, not by this skill.

2
Archivos escaneados
1,458
Líneas analizadas
3
Elementos de revisión
0
Falsos positivos ignorados

Factores de riesgo

🌐 Acceso a red (7)
📁 Acceso al sistema de archivos (1)
⚙️ Comandos externos (139)
SKILL.md:45-54 SKILL.md:54-58 SKILL.md:58-67 SKILL.md:67-80 SKILL.md:80-92 SKILL.md:104-115 SKILL.md:115-119 SKILL.md:119-135 SKILL.md:135-144 SKILL.md:144-164 SKILL.md:164-170 SKILL.md:170-177 SKILL.md:177-186 SKILL.md:186-207 SKILL.md:207-211 SKILL.md:211-224 SKILL.md:224-233 SKILL.md:233-264 SKILL.md:264-268 SKILL.md:268-307 SKILL.md:307-316 SKILL.md:316-353 SKILL.md:353-364 SKILL.md:364-380 SKILL.md:380-384 SKILL.md:384-427 SKILL.md:427-436 SKILL.md:436-453 SKILL.md:453-457 SKILL.md:457-472 SKILL.md:472-481 SKILL.md:481-487 SKILL.md:487-491 SKILL.md:491-499 SKILL.md:499-503 SKILL.md:503-509 SKILL.md:509-518 SKILL.md:518-544 SKILL.md:544-548 SKILL.md:548-573 SKILL.md:573-584 SKILL.md:584-598 SKILL.md:598-602 SKILL.md:602-609 SKILL.md:609-613 SKILL.md:613-622 SKILL.md:622-631 SKILL.md:631-650 SKILL.md:650-654 SKILL.md:654-667 SKILL.md:667-671 SKILL.md:671-688 SKILL.md:688-697 SKILL.md:697-704 SKILL.md:704-715 SKILL.md:715-730 SKILL.md:730-739 SKILL.md:739-745 SKILL.md:745-749 SKILL.md:749-755 SKILL.md:755-764 SKILL.md:764-770 SKILL.md:770-779 SKILL.md:779-786 SKILL.md:786-790 SKILL.md:790-797 SKILL.md:797-801 SKILL.md:801-808 SKILL.md:808-818 SKILL.md:818-857 SKILL.md:857-861 SKILL.md:861-896 SKILL.md:896-900 SKILL.md:900-940 SKILL.md:940-944 SKILL.md:944-970 SKILL.md:970-978 SKILL.md:978-996 SKILL.md:996-1000 SKILL.md:1000-1009 SKILL.md:1009-1017 SKILL.md:1017-1024 SKILL.md:1024-1028 SKILL.md:1028-1035 SKILL.md:1035-1039 SKILL.md:1039-1046 SKILL.md:1046-1094 SKILL.md:1094-1100 SKILL.md:1100-1104 SKILL.md:1104-1111 SKILL.md:1111-1115 SKILL.md:1115-1122 SKILL.md:1122-1150 SKILL.md:1150-1155 SKILL.md:1155-1159 SKILL.md:1159-1164 SKILL.md:1164-1182 SKILL.md:1182-1183 SKILL.md:1183-1184 SKILL.md:1184-1185 SKILL.md:1185-1193 SKILL.md:1193-1237 SKILL.md:1237-1243 SKILL.md:1243-1262 SKILL.md:60-61 SKILL.md:146 SKILL.md:155 SKILL.md:235 SKILL.md:238-241 SKILL.md:244 SKILL.md:254 SKILL.md:255 SKILL.md:270 SKILL.md:273 SKILL.md:276-277 SKILL.md:283-286 SKILL.md:304 SKILL.md:318 SKILL.md:319-320 SKILL.md:325 SKILL.md:328-330 SKILL.md:349 SKILL.md:366-367 SKILL.md:459 SKILL.md:633 SKILL.md:636 SKILL.md:638 SKILL.md:1197-1213 SKILL.md:1217 SKILL.md:1224 SKILL.md:58-67 SKILL.md:144-164 SKILL.md:233-264 SKILL.md:268-307 SKILL.md:316-353 SKILL.md:364-380 SKILL.md:457-472 SKILL.md:631-650 SKILL.md:1193-1237
Auditado por: claude

10 ene 2026, 13:22

Pure documentation skill containing only markdown guidance for GitHub project management workflows. No executable code, no network operations, no file system access, no environment variable reading. External tools (gh CLI, ruv-swarm) are invoked by the user, not by this skill.

1
Archivos escaneados
1,278
Líneas analizadas
0
Elementos de revisión
0
Falsos positivos ignorados
No se registraron hallazgos de seguridad confirmados en esta auditoría completada.
Auditado por: claude

10 ene 2026, 13:22

Pure documentation skill containing only markdown guidance for GitHub project management workflows. No executable code, no network operations, no file system access, no environment variable reading. External tools (gh CLI, ruv-swarm) are invoked by the user, not by this skill.

1
Archivos escaneados
1,278
Líneas analizadas
0
Elementos de revisión
0
Falsos positivos ignorados
No se registraron hallazgos de seguridad confirmados en esta auditoría completada.
Auditado por: claude

10 ene 2026, 13:22

Pure documentation skill containing only markdown guidance for GitHub project management workflows. No executable code, no network operations, no file system access, no environment variable reading. External tools (gh CLI, ruv-swarm) are invoked by the user, not by this skill.

1
Archivos escaneados
1,278
Líneas analizadas
0
Elementos de revisión
0
Falsos positivos ignorados
No se registraron hallazgos de seguridad confirmados en esta auditoría completada.
Auditado por: claude