Habilidades byted-mediakit-shared Historial de auditorías
📦

Historial de auditorías

byted-mediakit-shared - 1 auditoría

12 sept 2026, 11:54

Most alerts are false positives caused by Markdown backticks, Chinese text, and task identifiers. Several command blocks execute or update external software, while local media can be uploaded through cloud mode without explicit per-file consent.

3
Archivos escaneados
256
Líneas analizadas
11
Elementos de revisión
0
Falsos positivos ignorados

Preocupaciones de seguridad confirmadas (1)

Alto
Implicit Local Media Upload
The skill passes local paths to an adapter that uploads files. Cloud-first configuration can transmit sensitive media without explicit per-file consent.
The instructions explicitly state that the media adapter handles uploads and that current configuration may select Cloud-first mode.
Elementos de revisión de capacidades (9)

Estas son capacidades locales reales que pueden esperarse para esta habilidad, por lo que requieren revisión, pero no se cuentan como comportamiento malicioso confirmado.

Alto
Ruby/shell backtick execution · 3 apariciones
```bash
The block runs an unpinned npm package through npx with automatic confirmation. This exposes users to package supply-chain and installation risks.
Medio
Ruby/shell backtick execution
1. 通过本 Skill 或领域 Skill **实际执行** `mediakit-cli` 业务命令时,必须在同一次
The instruction explicitly directs the agent to execute mediakit-cli business commands. This grants an external process access to user media and configured services.
Medio
Ruby/shell backtick execution · 5 apariciones
```bash
The fenced block contains media processing and cloud task query commands with substituted values. Executing these commands can access files and network services.
Auditado por: codex