Habilidades archify Historial de auditorías
📦

Historial de auditorías

archify - 4 auditorías

Comparación de versiones

Cambios de capacidades y hallazgos entre versiones auditadas, primero las más recientes.

VersiónFechaResultadoElementos de revisiónCambio vs anterior
v4 Más reciente31 ago 2026, 15:49 1 confirmado6Sin cambios de capacidad
v3 31 ago 2026, 15:49 1 confirmado6Sin cambios de capacidad
v2 31 ago 2026, 15:49 1 confirmado6Sin cambios de capacidad
v1 31 ago 2026, 15:49 1 confirmado6Base

31 ago 2026, 15:49

Adjudication dismissed 394 of 400 presented matches as test fixtures, generated data, documentation, or bounded local tooling. Six confirmed URLs cause generated artifacts or the update workflow to contact remote hosts, and semantic review found that the updater runs automatically without prior disclosure. Static presentation was capped at 400 of 8,055 matches, so 7,655 unpresented matches require manual review before automatic publication. Static review was capped at 400/8055 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.

190
Archivos escaneados
144,837
Líneas analizadas
12
Elementos de revisión
0
Falsos positivos ignorados

Preocupaciones de seguridad confirmadas (1)

Medio
Undisclosed Automatic Update Check
The skill directs the agent to run a packaged update checker after creating the first candidate and to hide successful or failed checks. The checker uses a remote manifest, creating an unrequested network request and local cache state.
The instruction explicitly requires the check and suppresses disclosure in normal and failure cases. The packaged contract defines the remote manifest endpoint.
Elementos de revisión de capacidades (6)

Estas son capacidades locales reales que pueden esperarse para esta habilidad, por lo que requieren revisión, pero no se cuentan como comportamiento malicioso confirmado.

Bajo
Hardcoded URL · 2 apariciones
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
Opening the generated HTML initiates an external Google Fonts connection, which exposes viewer network metadata and contradicts fully self-contained offline behavior.
Bajo
Hardcoded URL · 2 apariciones
<link href="https://fonts.googleapis.com/css2?family=JetBrains+Mono:wght@400;500;600;700&display=swa
Opening the generated HTML initiates an external Google Fonts connection, which exposes viewer network metadata and contradicts fully self-contained offline behavior.
Bajo
Hardcoded URL
export const DEFAULT_MANIFEST_URL = 'https://tt-a1i.github.io/archify/skill-updates/archify/stable.j
This URL is the configured remote manifest used by the automatic update-check workflow. The check creates an outbound request after diagram authoring begins.
Bajo
Hardcoded URL
"updateManifestUrl": "https://tt-a1i.github.io/archify/skill-updates/archify/stable.json"
This URL is the configured remote manifest used by the automatic update-check workflow. The check creates an outbound request after diagram authoring begins.

Factores de riesgo

⚙️ Comandos externos (50)
🌐 Acceso a red (50)
📁 Acceso al sistema de archivos (50)
⚡ Contiene scripts (21)
🔑 Variables de entorno (50)
Auditado por: codex

31 ago 2026, 15:49

Adjudication dismissed 394 of 400 presented matches as test fixtures, generated data, documentation, or bounded local tooling. Six confirmed URLs cause generated artifacts or the update workflow to contact remote hosts, and semantic review found that the updater runs automatically without prior disclosure. Static presentation was capped at 400 of 8,055 matches, so 7,655 unpresented matches require manual review before automatic publication. Static review was capped at 400/8055 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.

190
Archivos escaneados
144,837
Líneas analizadas
12
Elementos de revisión
0
Falsos positivos ignorados

Preocupaciones de seguridad confirmadas (1)

Medio
Undisclosed Automatic Update Check
The skill directs the agent to run a packaged update checker after creating the first candidate and to hide successful or failed checks. The checker uses a remote manifest, creating an unrequested network request and local cache state.
The instruction explicitly requires the check and suppresses disclosure in normal and failure cases. The packaged contract defines the remote manifest endpoint.
Elementos de revisión de capacidades (6)

Estas son capacidades locales reales que pueden esperarse para esta habilidad, por lo que requieren revisión, pero no se cuentan como comportamiento malicioso confirmado.

Bajo
Hardcoded URL · 2 apariciones
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
Opening the generated HTML initiates an external Google Fonts connection, which exposes viewer network metadata and contradicts fully self-contained offline behavior.
Bajo
Hardcoded URL · 2 apariciones
<link href="https://fonts.googleapis.com/css2?family=JetBrains+Mono:wght@400;500;600;700&display=swa
Opening the generated HTML initiates an external Google Fonts connection, which exposes viewer network metadata and contradicts fully self-contained offline behavior.
Bajo
Hardcoded URL
export const DEFAULT_MANIFEST_URL = 'https://tt-a1i.github.io/archify/skill-updates/archify/stable.j
This URL is the configured remote manifest used by the automatic update-check workflow. The check creates an outbound request after diagram authoring begins.
Bajo
Hardcoded URL
"updateManifestUrl": "https://tt-a1i.github.io/archify/skill-updates/archify/stable.json"
This URL is the configured remote manifest used by the automatic update-check workflow. The check creates an outbound request after diagram authoring begins.

Factores de riesgo

⚙️ Comandos externos (50)
🌐 Acceso a red (50)
📁 Acceso al sistema de archivos (50)
⚡ Contiene scripts (21)
🔑 Variables de entorno (50)
Auditado por: codex

31 ago 2026, 15:49

Adjudication dismissed 394 of 400 presented matches as test fixtures, generated data, documentation, or bounded local tooling. Six confirmed URLs cause generated artifacts or the update workflow to contact remote hosts, and semantic review found that the updater runs automatically without prior disclosure. Static presentation was capped at 400 of 8,055 matches, so 7,655 unpresented matches require manual review before automatic publication. Static review was capped at 400/8055 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.

190
Archivos escaneados
144,837
Líneas analizadas
12
Elementos de revisión
0
Falsos positivos ignorados

Preocupaciones de seguridad confirmadas (1)

Medio
Undisclosed Automatic Update Check
The skill directs the agent to run a packaged update checker after creating the first candidate and to hide successful or failed checks. The checker uses a remote manifest, creating an unrequested network request and local cache state.
The instruction explicitly requires the check and suppresses disclosure in normal and failure cases. The packaged contract defines the remote manifest endpoint.
Elementos de revisión de capacidades (6)

Estas son capacidades locales reales que pueden esperarse para esta habilidad, por lo que requieren revisión, pero no se cuentan como comportamiento malicioso confirmado.

Bajo
Hardcoded URL · 2 apariciones
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
Opening the generated HTML initiates an external Google Fonts connection, which exposes viewer network metadata and contradicts fully self-contained offline behavior.
Bajo
Hardcoded URL · 2 apariciones
<link href="https://fonts.googleapis.com/css2?family=JetBrains+Mono:wght@400;500;600;700&display=swa
Opening the generated HTML initiates an external Google Fonts connection, which exposes viewer network metadata and contradicts fully self-contained offline behavior.
Bajo
Hardcoded URL
export const DEFAULT_MANIFEST_URL = 'https://tt-a1i.github.io/archify/skill-updates/archify/stable.j
This URL is the configured remote manifest used by the automatic update-check workflow. The check creates an outbound request after diagram authoring begins.
Bajo
Hardcoded URL
"updateManifestUrl": "https://tt-a1i.github.io/archify/skill-updates/archify/stable.json"
This URL is the configured remote manifest used by the automatic update-check workflow. The check creates an outbound request after diagram authoring begins.

Factores de riesgo

⚙️ Comandos externos (50)
🌐 Acceso a red (50)
📁 Acceso al sistema de archivos (50)
⚡ Contiene scripts (21)
🔑 Variables de entorno (50)
Auditado por: codex

31 ago 2026, 15:49

Adjudication dismissed 394 of 400 presented matches as test fixtures, generated data, documentation, or bounded local tooling. Six confirmed URLs cause generated artifacts or the update workflow to contact remote hosts, and semantic review found that the updater runs automatically without prior disclosure. Static presentation was capped at 400 of 8,055 matches, so 7,655 unpresented matches require manual review before automatic publication. Static review was capped at 400/8055 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.

190
Archivos escaneados
144,837
Líneas analizadas
12
Elementos de revisión
0
Falsos positivos ignorados

Preocupaciones de seguridad confirmadas (1)

Medio
Undisclosed Automatic Update Check
The skill directs the agent to run a packaged update checker after creating the first candidate and to hide successful or failed checks. The checker uses a remote manifest, creating an unrequested network request and local cache state.
The instruction explicitly requires the check and suppresses disclosure in normal and failure cases. The packaged contract defines the remote manifest endpoint.
Elementos de revisión de capacidades (6)

Estas son capacidades locales reales que pueden esperarse para esta habilidad, por lo que requieren revisión, pero no se cuentan como comportamiento malicioso confirmado.

Bajo
Hardcoded URL · 2 apariciones
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
Opening the generated HTML initiates an external Google Fonts connection, which exposes viewer network metadata and contradicts fully self-contained offline behavior.
Bajo
Hardcoded URL · 2 apariciones
<link href="https://fonts.googleapis.com/css2?family=JetBrains+Mono:wght@400;500;600;700&display=swa
Opening the generated HTML initiates an external Google Fonts connection, which exposes viewer network metadata and contradicts fully self-contained offline behavior.
Bajo
Hardcoded URL
export const DEFAULT_MANIFEST_URL = 'https://tt-a1i.github.io/archify/skill-updates/archify/stable.j
This URL is the configured remote manifest used by the automatic update-check workflow. The check creates an outbound request after diagram authoring begins.
Bajo
Hardcoded URL
"updateManifestUrl": "https://tt-a1i.github.io/archify/skill-updates/archify/stable.json"
This URL is the configured remote manifest used by the automatic update-check workflow. The check creates an outbound request after diagram authoring begins.

Factores de riesgo

⚙️ Comandos externos (50)
🌐 Acceso a red (50)
📁 Acceso al sistema de archivos (50)
⚡ Contiene scripts (21)
🔑 Variables de entorno (50)
Auditado por: codex