Historique des audits
sast-configuration - 4 audits
Version de l’audit 4
Dernier SûrJan 17, 2026, 09:55 AM
This is a pure documentation skill containing only guidance and example commands for configuring SAST tools. All 32 static findings are false positives triggered by security-related terminology in documentation. The skill describes legitimate defensive security practices (Semgrep, SonarQube, CodeQL configuration) with no executable code, file access, network calls, or command execution. Behavior matches stated purpose of providing SAST configuration guidance.
Facteurs de risque
🌐 Accès réseau (2)
⚙️ Commandes externes (11)
📁 Accès au système de fichiers (3)
Version de l’audit 3
SûrJan 17, 2026, 09:55 AM
This is a pure documentation skill containing only guidance and example commands for configuring SAST tools. All 32 static findings are false positives triggered by security-related terminology in documentation. The skill describes legitimate defensive security practices (Semgrep, SonarQube, CodeQL configuration) with no executable code, file access, network calls, or command execution. Behavior matches stated purpose of providing SAST configuration guidance.
Facteurs de risque
🌐 Accès réseau (2)
⚙️ Commandes externes (11)
📁 Accès au système de fichiers (3)
Version de l’audit 2
SûrJan 4, 2026, 04:20 PM
Pure documentation skill containing only guidance and example commands for configuring SAST tools. No executable code, file access, network calls, or command execution patterns detected. Behavior matches stated purpose.
Version de l’audit 1
SûrJan 4, 2026, 04:20 PM
Pure documentation skill containing only guidance and example commands for configuring SAST tools. No executable code, file access, network calls, or command execution patterns detected. Behavior matches stated purpose.