監査履歴
api-mitmproxy - 6 監査
監査バージョン 6
最新 高リスクJun 28, 2026, 06:12 AM
The static findings are mostly documentation and template examples, not hidden executable payloads. However, the skill provides high-impact dual-use guidance for HTTPS interception, credential capture, certificate pinning bypass, exposed proxy listeners, request modification, and copied CI command execution patterns. No prompt injection attempt or confirmed malicious marketplace behavior was found, but publication should require stricter safeguards and warnings.
高リスクの問題 (2)
中リスクの問題 (3)
低リスクの問題 (2)
リスク要因
⚙️ 外部コマンド (87)
🌐 ネットワークアクセス (39)
📁 ファイルシステムへのアクセス (11)
🔑 環境変数 (27)
⚡ スクリプトを含む (2)
検出されたパターン
監査バージョン 5
低リスクJan 16, 2026, 03:11 PM
Documentation-only skill describing mitmproxy, a legitimate open-source security testing tool. Contains no executable code - only documentation for authorized security testing workflows. All 234 static findings are false positives: patterns flagged as dangerous (command execution, credential access, network operations) are legitimate documentation of security tool capabilities. The skill explicitly includes security considerations warning about authorization, sensitive data handling, and compliance requirements. No evidence of malicious intent or harmful patterns found after semantic evaluation.
リスク要因
⚙️ 外部コマンド (1)
🌐 ネットワークアクセス (1)
📁 ファイルシステムへのアクセス (1)
🔑 環境変数 (1)
⚡ スクリプトを含む (1)
監査バージョン 4
低リスクJan 16, 2026, 03:11 PM
Documentation-only skill describing mitmproxy, a legitimate open-source security testing tool. Contains no executable code - only documentation for authorized security testing workflows. All 234 static findings are false positives: patterns flagged as dangerous (command execution, credential access, network operations) are legitimate documentation of security tool capabilities. The skill explicitly includes security considerations warning about authorization, sensitive data handling, and compliance requirements. No evidence of malicious intent or harmful patterns found after semantic evaluation.
リスク要因
⚙️ 外部コマンド (1)
🌐 ネットワークアクセス (1)
📁 ファイルシステムへのアクセス (1)
🔑 環境変数 (1)
⚡ スクリプトを含む (1)
監査バージョン 3
低リスクJan 10, 2026, 10:15 AM
Documentation-only skill describing mitmproxy, a legitimate open-source security tool. Contains no executable scripts. Includes security considerations for proper authorization and sensitive data handling. Content is defensive and educational.
監査バージョン 2
低リスクJan 10, 2026, 10:15 AM
Documentation-only skill describing mitmproxy, a legitimate open-source security tool. Contains no executable scripts. Includes security considerations for proper authorization and sensitive data handling. Content is defensive and educational.
監査バージョン 1
低リスクJan 10, 2026, 10:15 AM
Documentation-only skill describing mitmproxy, a legitimate open-source security tool. Contains no executable scripts. Includes security considerations for proper authorization and sensitive data handling. Content is defensive and educational.