Historial de auditorías
ghe-changelog - 8 auditorías
Comparación de versiones
Cambios de capacidades y hallazgos entre versiones auditadas, primero las más recientes.
| Versión | Fecha | Resultado | Elementos de revisión | Cambio vs anterior |
|---|---|---|---|---|
| v8 Más reciente | 6 jul 2026, 12:17 | 2 confirmado | 48 | Sin cambios de capacidad |
| v7 | 6 jul 2026, 12:17 | 2 confirmado | 48 | Sin cambios de capacidad |
| v6 | 29 jun 2026, 23:48 | 4 confirmado | 0 | Sin cambios de capacidad |
| v5 | 17 ene 2026, 06:57 | Sin hallazgos confirmados | 0 | Sin cambios de capacidad |
| v4 | 17 ene 2026, 06:57 | Sin hallazgos confirmados | 0 | Comandos externosAcceso al sistema de archivos |
| v3 | 10 ene 2026, 14:35 | Sin hallazgos confirmados | 0 | Sin cambios de capacidad |
| v2 | 10 ene 2026, 14:35 | Sin hallazgos confirmados | 0 | Sin cambios de capacidad |
| v1 | 10 ene 2026, 14:35 | Sin hallazgos confirmados | 0 | Base |
6 jul 2026, 12:17
The skill contains legitimate changelog automation, but it directs agents to run shell, git, and GitHub CLI commands and to write project files. The most serious concerns are the prompt-injection-style absolute instruction language, mandatory external report posting, and permission to write ~/.claude configuration.
Preocupaciones de seguridad confirmadas (2)
Elementos de revisión de capacidades (48)
Estas son capacidades locales reales que pueden esperarse para esta habilidad, por lo que requieren revisión, pero no se cuentan como comportamiento malicioso confirmado.
Factores de riesgo
⚙️ Comandos externos (62)
📁 Acceso al sistema de archivos (6)
6 jul 2026, 12:17
The skill contains legitimate changelog automation, but it directs agents to run shell, git, and GitHub CLI commands and to write project files. The most serious concerns are the prompt-injection-style absolute instruction language, mandatory external report posting, and permission to write ~/.claude configuration.
Preocupaciones de seguridad confirmadas (2)
Elementos de revisión de capacidades (48)
Estas son capacidades locales reales que pueden esperarse para esta habilidad, por lo que requieren revisión, pero no se cuentan como comportamiento malicioso confirmado.
Factores de riesgo
⚙️ Comandos externos (62)
📁 Acceso al sistema de archivos (6)
29 jun 2026, 23:48
Static external-command findings are mostly legitimate shell examples for changelog automation, but they still execute git, sed, gh, and file mutation commands if followed. The static weak-cryptography matches appear to be false positives from changelog and markdown text. Publication should be blocked because the skill includes prompt-injection style instructions that demand verbatim obedience to user specifications with no exceptions.
Preocupaciones de seguridad confirmadas (4)
Falsos positivos estáticos ignorados (2)
Estas coincidencias estáticas fueron descartadas por la revisión semántica o coincidieron con tokens solo de esquema, por lo que se muestran por transparencia, pero no afectan la puntuación de calidad.
Factores de riesgo
⚙️ Comandos externos (7)
📁 Acceso al sistema de archivos (3)
Patrones detectados
17 ene 2026, 06:57
Pure documentation skill containing only reference bash scripts for changelog management. All static findings are FALSE POSITIVES - the scanner misidentified git command documentation as security risks. The skill contains no executable code, makes no network calls, and performs no sensitive operations. Shell command patterns in documentation are legitimate git operations for version tracking.
Factores de riesgo
⚙️ Comandos externos (62)
📁 Acceso al sistema de archivos (6)
17 ene 2026, 06:57
Pure documentation skill containing only reference bash scripts for changelog management. All static findings are FALSE POSITIVES - the scanner misidentified git command documentation as security risks. The skill contains no executable code, makes no network calls, and performs no sensitive operations. Shell command patterns in documentation are legitimate git operations for version tracking.
Factores de riesgo
⚙️ Comandos externos (62)
📁 Acceso al sistema de archivos (6)
10 ene 2026, 14:35
Pure prompt-based skill containing only documentation and example bash scripts embedded as reference material. No executable files, network calls, or sensitive operations. The skill provides instructions for changelog management using git commands.
10 ene 2026, 14:35
Pure prompt-based skill containing only documentation and example bash scripts embedded as reference material. No executable files, network calls, or sensitive operations. The skill provides instructions for changelog management using git commands.
10 ene 2026, 14:35
Pure prompt-based skill containing only documentation and example bash scripts embedded as reference material. No executable files, network calls, or sensitive operations. The skill provides instructions for changelog management using git commands.