Habilidades vue-pinia-best-practices Historial de auditorías
📦

Historial de auditorías

vue-pinia-best-practices - 5 auditorías

Comparación de versiones

Cambios de capacidades y hallazgos entre versiones auditadas, primero las más recientes.

VersiónFechaResultadoElementos de revisiónCambio vs anterior
v5 Más reciente7 jul 2026, 07:00 Sin hallazgos confirmados0Sin cambios de capacidad
v4 7 jul 2026, 07:00 Sin hallazgos confirmados0Sin cambios de capacidad
v3 30 jun 2026, 22:58 Sin hallazgos confirmados1Sin cambios de capacidad
v2 30 jun 2026, 22:58 Sin hallazgos confirmados1Contiene scriptsAcceso a redComandos externos
v1 8 feb 2026, 08:41 Sin hallazgos confirmados0Base

7 jul 2026, 07:00

AI review found the static findings are documentation examples, not executable skill behavior. Dynamic imports, fetch calls, Authorization headers, and Object.keys appear inside Pinia guidance snippets using local app paths; no prompt injection, credential exfiltration, or command execution intent was found.

7
Archivos escaneados
1,387
Líneas analizadas
3
Elementos de revisión
0
Falsos positivos ignorados
Auditado por: codex

7 jul 2026, 07:00

AI review found the static findings are documentation examples, not executable skill behavior. Dynamic imports, fetch calls, Authorization headers, and Object.keys appear inside Pinia guidance snippets using local app paths; no prompt injection, credential exfiltration, or command execution intent was found.

7
Archivos escaneados
1,387
Líneas analizadas
3
Elementos de revisión
0
Falsos positivos ignorados
Auditado por: codex

30 jun 2026, 22:58

Static analysis flagged dynamic imports, shell-like backticks, fetch calls, hardcoded documentation URLs, localStorage mentions, and weak-crypto keyword matches. Manual review found these patterns inside Markdown tutorials and Vue or JavaScript examples, not executable skill code. No prompt injection, credential exfiltration, or malicious command execution intent was found.

7
Archivos escaneados
1,387
Líneas analizadas
4
Elementos de revisión
1
Falsos positivos ignorados
Necesita revisar los hallazgos (1)

Estos hallazgos provienen de veredictos de auditoría heredados inciertos, por lo que requieren revisión, pero no se cuentan como problemas de seguridad confirmados.

Bajo
Educational Snippets Mention Tokens and Persistence
Some examples demonstrate Authorization headers, authToken state, and persisted store behavior. This is legitimate Pinia teaching content, but users should avoid persisting secrets or exposing sensitive state without project-specific controls.
The examples are clearly instructional and use relative API paths, not external exfiltration endpoints. The residual concern is misuse by users who copy persistence patterns for sensitive tokens.
Falsos positivos estáticos ignorados (1)

Estas coincidencias estáticas fueron descartadas por la revisión semántica o coincidieron con tokens solo de esquema, por lo que se muestran por transparencia, pero no afectan la puntuación de calidad.

Bajo
Static Findings Dismissed as Markdown Examples
The external command, weak-crypto, system reconnaissance, and script detections occur in Markdown prose, checklists, links, or fenced Vue and JavaScript examples. They are not runnable skill installation scripts and do not create command execution risk by themselves.
The cited content is Markdown guidance and code-fenced tutorial material. I found no executable script file or install hook that would run these snippets automatically.
Auditado por: codex

30 jun 2026, 22:58

Static analysis flagged dynamic imports, shell-like backticks, fetch calls, hardcoded documentation URLs, localStorage mentions, and weak-crypto keyword matches. Manual review found these patterns inside Markdown tutorials and Vue or JavaScript examples, not executable skill code. No prompt injection, credential exfiltration, or malicious command execution intent was found.

7
Archivos escaneados
1,387
Líneas analizadas
4
Elementos de revisión
1
Falsos positivos ignorados
Necesita revisar los hallazgos (1)

Estos hallazgos provienen de veredictos de auditoría heredados inciertos, por lo que requieren revisión, pero no se cuentan como problemas de seguridad confirmados.

Bajo
Educational Snippets Mention Tokens and Persistence
Some examples demonstrate Authorization headers, authToken state, and persisted store behavior. This is legitimate Pinia teaching content, but users should avoid persisting secrets or exposing sensitive state without project-specific controls.
The examples are clearly instructional and use relative API paths, not external exfiltration endpoints. The residual concern is misuse by users who copy persistence patterns for sensitive tokens.
Falsos positivos estáticos ignorados (1)

Estas coincidencias estáticas fueron descartadas por la revisión semántica o coincidieron con tokens solo de esquema, por lo que se muestran por transparencia, pero no afectan la puntuación de calidad.

Bajo
Static Findings Dismissed as Markdown Examples
The external command, weak-crypto, system reconnaissance, and script detections occur in Markdown prose, checklists, links, or fenced Vue and JavaScript examples. They are not runnable skill installation scripts and do not create command execution risk by themselves.
The cited content is Markdown guidance and code-fenced tutorial material. I found no executable script file or install hook that would run these snippets automatically.
Auditado por: codex

8 feb 2026, 08:41

Static analysis detected 215 patterns in markdown documentation files. All findings are FALSE POSITIVES. The 'Ruby/shell backtick execution' patterns are markdown code blocks using backticks for syntax highlighting. The 'Weak cryptographic algorithm' and 'System reconnaissance' findings are false positives from documentation text. No executable code, network calls, or file system operations exist in this skill. Risk level: safe.

7
Archivos escaneados
1,387
Líneas analizadas
0
Elementos de revisión
0
Falsos positivos ignorados
No se registraron hallazgos de seguridad confirmados en esta auditoría completada.
Auditado por: claude