📦

監査履歴

analysis-tshark - 6 監査

監査バージョン 6

最新 高リスク

Jun 28, 2026, 06:07 AM

Static findings are mostly documentation and template examples, but the core skill intentionally provides privileged packet capture, credential extraction, and TLS decryption workflows. No prompt injection or covert exfiltration was found, so this is not blocked as malicious. The dual-use credential and network interception capabilities make it unsuitable for publication without strong gating and authorization controls.

5
スキャンされたファイル
2,158
解析された行数
13
検出結果
codex
監査者

高リスクの問題 (3)

Privileged Live Packet Capture
The skill instructs users to run TShark with sudo on live interfaces and to grant packet capture capabilities. This can intercept traffic outside an authorized scope and expose private communications.
Credential and Hash Extraction Workflows
The skill provides TShark filters for HTTP Basic Auth, FTP passwords, NTLM responses, Kerberos names, POP3 credentials, and IMAP login data. These are legitimate for forensics but can directly enable credential harvesting.
TLS Decryption Material Handling
The troubleshooting guidance uses SSL key log files and server private keys to decrypt TLS traffic. Misuse could expose protected communications from packet captures.
中リスクの問題 (3)
Sensitive File and Object Extraction
The skill shows how to export HTTP, SMB, DICOM, and email objects from packet captures and reconstruct files. This can recover sensitive documents or medical and email content from network traffic.
Automated Alert Pipeline Can Distribute Sensitive Traffic Data
The automation example pipes captured network fields into logs and email alerts. If copied without redaction, sensitive hostnames, IP addresses, or request metadata could be distributed broadly.
Pipe-to-Shell Installer in CI Template
The CI template installs tfsec by piping a remote script directly to bash. This is a risky supply-chain pattern if users copy the template into production workflows.
低リスクの問題 (2)
Static Scanner Hits in Educational Templates
Several reported XSS, hardcoded secret, weak crypto, and command patterns appear in rule examples or documentation templates. They demonstrate vulnerable and fixed code rather than active skill behavior.
No Prompt Injection Evidence Found
A targeted review did not find override phrases or instructions telling the evaluator to skip security analysis. This lowers the likelihood of hidden marketplace manipulation.

検出されたパターン

sudo TShark Capture CommandsCredential Extraction FiltersRemote Script Piped to BashTLS Key Material Configuration

監査バージョン 5

安全

Jan 16, 2026, 03:09 PM

This is a documentation-only skill containing no executable code. All content describes legitimate defensive security operations using TShark (Wireshark CLI). The static analyzer flagged 298 findings, but all are FALSE POSITIVES because they are detecting example commands and security terminology in documentation, not actual executable code. The skill includes proper authorization warnings, legal compliance guidance, and defensive considerations for protecting networks against unauthorized packet capture.

6
スキャンされたファイル
2,372
解析された行数
5
検出結果
claude
監査者
セキュリティ問題は見つかりませんでした

リスク要因

⚙️ 外部コマンド (146)
assets/ci-config-template.yml:298 assets/ci-config-template.yml:301 assets/ci-config-template.yml:304 assets/ci-config-template.yml:307 assets/ci-config-template.yml:310 assets/ci-config-template.yml:134 assets/ci-config-template.yml:250 assets/ci-config-template.yml:291 references/EXAMPLE.md:54-74 references/EXAMPLE.md:74-95 references/EXAMPLE.md:95-108 references/EXAMPLE.md:108-111 references/EXAMPLE.md:111-118 references/EXAMPLE.md:118-122 references/EXAMPLE.md:122-129 references/EXAMPLE.md:129-135 references/EXAMPLE.md:135-151 references/EXAMPLE.md:151-154 references/EXAMPLE.md:154-162 references/EXAMPLE.md:162-296 references/EXAMPLE.md:296-306 references/EXAMPLE.md:306-309 references/EXAMPLE.md:309-318 references/EXAMPLE.md:318-333 references/EXAMPLE.md:333-342 references/EXAMPLE.md:342-346 references/EXAMPLE.md:346-354 references/EXAMPLE.md:354-358 references/EXAMPLE.md:358-361 references/EXAMPLE.md:361-371 references/EXAMPLE.md:371-404 references/EXAMPLE.md:404-414 references/EXAMPLE.md:414-447 references/EXAMPLE.md:447-451 references/EXAMPLE.md:451-472 references/EXAMPLE.md:472-476 references/EXAMPLE.md:476-537 references/WORKFLOW_CHECKLIST.md:74 SKILL.md:36-51 SKILL.md:51-82 SKILL.md:82-98 SKILL.md:98-111 SKILL.md:111-126 SKILL.md:126-129 SKILL.md:129-130 SKILL.md:130-131 SKILL.md:131-132 SKILL.md:132-133 SKILL.md:133-139 SKILL.md:139-157 SKILL.md:157-160 SKILL.md:160-161 SKILL.md:161-162 SKILL.md:162-163 SKILL.md:163-164 SKILL.md:164-165 SKILL.md:165-171 SKILL.md:171-189 SKILL.md:189-193 SKILL.md:193-208 SKILL.md:208-216 SKILL.md:216-228 SKILL.md:228-232 SKILL.md:232-244 SKILL.md:244-248 SKILL.md:248-260 SKILL.md:260-264 SKILL.md:264-273 SKILL.md:273-281 SKILL.md:281-287 SKILL.md:287-291 SKILL.md:291-297 SKILL.md:297-301 SKILL.md:301-307 SKILL.md:307-311 SKILL.md:311-320 SKILL.md:320-326 SKILL.md:326-338 SKILL.md:338-342 SKILL.md:342-348 SKILL.md:348-354 SKILL.md:354-369 SKILL.md:369-375 SKILL.md:375-396 SKILL.md:396-439 SKILL.md:439-452 SKILL.md:452-456 SKILL.md:456-471 SKILL.md:471-475 SKILL.md:475-487 SKILL.md:487-491 SKILL.md:491-503 SKILL.md:503-507 SKILL.md:507-522 SKILL.md:522-530 SKILL.md:530-539 SKILL.md:539-543 SKILL.md:543-556 SKILL.md:556-563 SKILL.md:563-572 SKILL.md:572-577 SKILL.md:577-587 SKILL.md:587-592 SKILL.md:592-601 SKILL.md:601-606 SKILL.md:606-612 SKILL.md:359 SKILL.md:441 SKILL.md:552 SKILL.md:354-369 SKILL.md:439-452 SKILL.md:543-556 SKILL.md:548 SKILL.md:544 SKILL.md:38 SKILL.md:41 SKILL.md:87 SKILL.md:90 SKILL.md:91 SKILL.md:94 SKILL.md:97 SKILL.md:113 SKILL.md:116 SKILL.md:119 SKILL.md:122 SKILL.md:125 SKILL.md:141 SKILL.md:144 SKILL.md:147 SKILL.md:150 SKILL.md:153 SKILL.md:156 SKILL.md:441 SKILL.md:458 SKILL.md:477 SKILL.md:509 SKILL.md:550 SKILL.md:564-565 SKILL.md:565 SKILL.md:568 SKILL.md:569 SKILL.md:581-582 SKILL.md:582 SKILL.md:594 SKILL.md:597 SKILL.md:600
🌐 ネットワークアクセス (38)
📁 ファイルシステムへのアクセス (2)
🔑 環境変数 (27)
⚡ スクリプトを含む (2)

監査バージョン 4

安全

Jan 16, 2026, 03:09 PM

This is a documentation-only skill containing no executable code. All content describes legitimate defensive security operations using TShark (Wireshark CLI). The static analyzer flagged 298 findings, but all are FALSE POSITIVES because they are detecting example commands and security terminology in documentation, not actual executable code. The skill includes proper authorization warnings, legal compliance guidance, and defensive considerations for protecting networks against unauthorized packet capture.

6
スキャンされたファイル
2,372
解析された行数
5
検出結果
claude
監査者
セキュリティ問題は見つかりませんでした

リスク要因

⚙️ 外部コマンド (146)
assets/ci-config-template.yml:298 assets/ci-config-template.yml:301 assets/ci-config-template.yml:304 assets/ci-config-template.yml:307 assets/ci-config-template.yml:310 assets/ci-config-template.yml:134 assets/ci-config-template.yml:250 assets/ci-config-template.yml:291 references/EXAMPLE.md:54-74 references/EXAMPLE.md:74-95 references/EXAMPLE.md:95-108 references/EXAMPLE.md:108-111 references/EXAMPLE.md:111-118 references/EXAMPLE.md:118-122 references/EXAMPLE.md:122-129 references/EXAMPLE.md:129-135 references/EXAMPLE.md:135-151 references/EXAMPLE.md:151-154 references/EXAMPLE.md:154-162 references/EXAMPLE.md:162-296 references/EXAMPLE.md:296-306 references/EXAMPLE.md:306-309 references/EXAMPLE.md:309-318 references/EXAMPLE.md:318-333 references/EXAMPLE.md:333-342 references/EXAMPLE.md:342-346 references/EXAMPLE.md:346-354 references/EXAMPLE.md:354-358 references/EXAMPLE.md:358-361 references/EXAMPLE.md:361-371 references/EXAMPLE.md:371-404 references/EXAMPLE.md:404-414 references/EXAMPLE.md:414-447 references/EXAMPLE.md:447-451 references/EXAMPLE.md:451-472 references/EXAMPLE.md:472-476 references/EXAMPLE.md:476-537 references/WORKFLOW_CHECKLIST.md:74 SKILL.md:36-51 SKILL.md:51-82 SKILL.md:82-98 SKILL.md:98-111 SKILL.md:111-126 SKILL.md:126-129 SKILL.md:129-130 SKILL.md:130-131 SKILL.md:131-132 SKILL.md:132-133 SKILL.md:133-139 SKILL.md:139-157 SKILL.md:157-160 SKILL.md:160-161 SKILL.md:161-162 SKILL.md:162-163 SKILL.md:163-164 SKILL.md:164-165 SKILL.md:165-171 SKILL.md:171-189 SKILL.md:189-193 SKILL.md:193-208 SKILL.md:208-216 SKILL.md:216-228 SKILL.md:228-232 SKILL.md:232-244 SKILL.md:244-248 SKILL.md:248-260 SKILL.md:260-264 SKILL.md:264-273 SKILL.md:273-281 SKILL.md:281-287 SKILL.md:287-291 SKILL.md:291-297 SKILL.md:297-301 SKILL.md:301-307 SKILL.md:307-311 SKILL.md:311-320 SKILL.md:320-326 SKILL.md:326-338 SKILL.md:338-342 SKILL.md:342-348 SKILL.md:348-354 SKILL.md:354-369 SKILL.md:369-375 SKILL.md:375-396 SKILL.md:396-439 SKILL.md:439-452 SKILL.md:452-456 SKILL.md:456-471 SKILL.md:471-475 SKILL.md:475-487 SKILL.md:487-491 SKILL.md:491-503 SKILL.md:503-507 SKILL.md:507-522 SKILL.md:522-530 SKILL.md:530-539 SKILL.md:539-543 SKILL.md:543-556 SKILL.md:556-563 SKILL.md:563-572 SKILL.md:572-577 SKILL.md:577-587 SKILL.md:587-592 SKILL.md:592-601 SKILL.md:601-606 SKILL.md:606-612 SKILL.md:359 SKILL.md:441 SKILL.md:552 SKILL.md:354-369 SKILL.md:439-452 SKILL.md:543-556 SKILL.md:548 SKILL.md:544 SKILL.md:38 SKILL.md:41 SKILL.md:87 SKILL.md:90 SKILL.md:91 SKILL.md:94 SKILL.md:97 SKILL.md:113 SKILL.md:116 SKILL.md:119 SKILL.md:122 SKILL.md:125 SKILL.md:141 SKILL.md:144 SKILL.md:147 SKILL.md:150 SKILL.md:153 SKILL.md:156 SKILL.md:441 SKILL.md:458 SKILL.md:477 SKILL.md:509 SKILL.md:550 SKILL.md:564-565 SKILL.md:565 SKILL.md:568 SKILL.md:569 SKILL.md:581-582 SKILL.md:582 SKILL.md:594 SKILL.md:597 SKILL.md:600
🌐 ネットワークアクセス (38)
📁 ファイルシステムへのアクセス (2)
🔑 環境変数 (27)
⚡ スクリプトを含む (2)

監査バージョン 3

安全

Jan 10, 2026, 10:14 AM

This is a prompt-only documentation skill containing no executable code. All content describes legitimate security operations using TShark (Wireshark CLI). The documentation includes proper authorization warnings and defensive considerations. No network calls, file system access, or code execution capabilities exist in this skill.

5
スキャンされたファイル
1,823
解析された行数
0
検出結果
claude
監査者
セキュリティ問題は見つかりませんでした

監査バージョン 2

安全

Jan 10, 2026, 10:14 AM

This is a prompt-only documentation skill containing no executable code. All content describes legitimate security operations using TShark (Wireshark CLI). The documentation includes proper authorization warnings and defensive considerations. No network calls, file system access, or code execution capabilities exist in this skill.

5
スキャンされたファイル
1,823
解析された行数
0
検出結果
claude
監査者
セキュリティ問題は見つかりませんでした

監査バージョン 1

安全

Jan 10, 2026, 10:14 AM

This is a prompt-only documentation skill containing no executable code. All content describes legitimate security operations using TShark (Wireshark CLI). The documentation includes proper authorization warnings and defensive considerations. No network calls, file system access, or code execution capabilities exist in this skill.

5
スキャンされたファイル
1,823
解析された行数
0
検出結果
claude
監査者
セキュリティ問題は見つかりませんでした