Historial de auditorías
github - 8 auditorías
Comparación de versiones
Cambios de capacidades y hallazgos entre versiones auditadas, primero las más recientes.
| Versión | Fecha | Resultado | Elementos de revisión | Cambio vs anterior |
|---|---|---|---|---|
| v8 Más reciente | 5 jul 2026, 15:00 | 1 confirmado | 0 | Sin cambios de capacidad |
| v7 | 5 jul 2026, 15:00 | 1 confirmado | 0 | Sin cambios de capacidad |
| v6 | 30 jun 2026, 00:51 | 1 confirmado | 0 | Acceso a redAcceso al sistema de archivos |
| v5 | 17 ene 2026, 05:20 | Sin hallazgos confirmados | 0 | Sin cambios de capacidad |
| v4 | 17 ene 2026, 05:20 | Sin hallazgos confirmados | 0 | Sin cambios de capacidad |
| v3 | 10 ene 2026, 14:36 | 1 confirmado | 2 | Sin cambios de capacidad |
| v2 | 10 ene 2026, 14:36 | 1 confirmado | 2 | Sin cambios de capacidad |
| v1 | 10 ene 2026, 14:36 | 1 confirmado | 2 | Base |
5 jul 2026, 15:00
The static Ruby backtick findings are false positives caused by Markdown inline code and fenced command examples. No evidence found of prompt injection or hidden malicious instructions. A medium semantic risk remains because the skill lists state-changing GitHub actions without a required confirmation rule.
Preocupaciones de seguridad confirmadas (1)
Factores de riesgo
⚙️ Comandos externos (36)
5 jul 2026, 15:00
The static Ruby backtick findings are false positives caused by Markdown inline code and fenced command examples. No evidence found of prompt injection or hidden malicious instructions. A medium semantic risk remains because the skill lists state-changing GitHub actions without a required confirmation rule.
Preocupaciones de seguridad confirmadas (1)
Factores de riesgo
⚙️ Comandos externos (36)
30 jun 2026, 00:51
The external command findings are true positives because the skill instructs use of git and gh CLI commands. The commands match the stated GitHub purpose and show no malicious intent, but several examples can mutate authenticated repositories. The weak cryptography findings are false positives from prose and placeholder text, not cryptographic code.
Preocupaciones de seguridad confirmadas (1)
Falsos positivos estáticos ignorados (1)
Estas coincidencias estáticas fueron descartadas por la revisión semántica o coincidieron con tokens solo de esquema, por lo que se muestran por transparencia, pero no afectan la puntuación de calidad.
Factores de riesgo
⚙️ Comandos externos (7)
Patrones detectados
17 ene 2026, 05:20
This skill is documentation-only for the GitHub CLI tool. All 55 static findings are false positives caused by the analyzer misinterpreting documentation metadata and GitHub terminology as security issues. The skill enables safe gh CLI command execution through the official GitHub CLI tool.
Factores de riesgo
⚙️ Comandos externos (1)
🌐 Acceso a red (1)
📁 Acceso al sistema de archivos (1)
17 ene 2026, 05:20
This skill is documentation-only for the GitHub CLI tool. All 55 static findings are false positives caused by the analyzer misinterpreting documentation metadata and GitHub terminology as security issues. The skill enables safe gh CLI command execution through the official GitHub CLI tool.
Factores de riesgo
⚙️ Comandos externos (1)
🌐 Acceso a red (1)
📁 Acceso al sistema de archivos (1)
10 ene 2026, 14:36
This skill provides GitHub CLI command documentation. While the documentation itself is safe, it enables execution of gh commands that interact with GitHub's API and modify local repositories. Requires proper input sanitization to prevent command injection.
Preocupaciones de seguridad confirmadas (1)
Elementos de revisión de capacidades (2)
Estas son capacidades locales reales que pueden esperarse para esta habilidad, por lo que requieren revisión, pero no se cuentan como comportamiento malicioso confirmado.
Factores de riesgo
⚙️ Comandos externos (1)
🌐 Acceso a red (1)
📁 Acceso al sistema de archivos (1)
10 ene 2026, 14:36
This skill provides GitHub CLI command documentation. While the documentation itself is safe, it enables execution of gh commands that interact with GitHub's API and modify local repositories. Requires proper input sanitization to prevent command injection.
Preocupaciones de seguridad confirmadas (1)
Elementos de revisión de capacidades (2)
Estas son capacidades locales reales que pueden esperarse para esta habilidad, por lo que requieren revisión, pero no se cuentan como comportamiento malicioso confirmado.
Factores de riesgo
⚙️ Comandos externos (1)
🌐 Acceso a red (1)
📁 Acceso al sistema de archivos (1)
10 ene 2026, 14:36
This skill provides GitHub CLI command documentation. While the documentation itself is safe, it enables execution of gh commands that interact with GitHub's API and modify local repositories. Requires proper input sanitization to prevent command injection.
Preocupaciones de seguridad confirmadas (1)
Elementos de revisión de capacidades (2)
Estas son capacidades locales reales que pueden esperarse para esta habilidad, por lo que requieren revisión, pero no se cuentan como comportamiento malicioso confirmado.