監査履歴
sast-horusec - 6 監査
監査バージョン 6
最新 高リスクJun 28, 2026, 06:08 AM
Static analysis flagged many command, network, environment, filesystem, and script patterns. Most findings are documentation examples or legitimate SAST workflow guidance, but the Docker socket mount, world-writable Docker socket advice, and pipe-to-shell installers are confirmed high-risk operational patterns. No evidence found of prompt injection or confirmed malicious intent, so the skill is not blocked but should not publish without revisions.
高リスクの問題 (3)
中リスクの問題 (2)
低リスクの問題 (3)
リスク要因
⚙️ 外部コマンド (6)
🌐 ネットワークアクセス (4)
📁 ファイルシステムへのアクセス (1)
🔑 環境変数 (3)
⚡ スクリプトを含む (1)
検出されたパターン
監査バージョン 5
安全Jan 16, 2026, 04:03 PM
Documentation-only skill containing no executable code. All static findings are false positives - patterns detected are legitimate documentation examples showing vulnerable code patterns that Horusec scanner is designed to detect. Docker socket references and command examples are for running Horusec CLI tool, not for malicious purposes. All URLs point to legitimate security resources (Horusec, OWASP, CWE).
リスク要因
⚙️ 外部コマンド (99)
🌐 ネットワークアクセス (22)
📁 ファイルシステムへのアクセス (2)
🔑 環境変数 (27)
⚡ スクリプトを含む (2)
監査バージョン 4
安全Jan 16, 2026, 04:03 PM
Documentation-only skill containing no executable code. All static findings are false positives - patterns detected are legitimate documentation examples showing vulnerable code patterns that Horusec scanner is designed to detect. Docker socket references and command examples are for running Horusec CLI tool, not for malicious purposes. All URLs point to legitimate security resources (Horusec, OWASP, CWE).
リスク要因
⚙️ 外部コマンド (99)
🌐 ネットワークアクセス (22)
📁 ファイルシステムへのアクセス (2)
🔑 環境変数 (27)
⚡ スクリプトを含む (2)
監査バージョン 3
安全Jan 10, 2026, 10:57 AM
This skill contains only documentation and configuration templates. No executable scripts, no network calls, and no direct filesystem access. The skill guides users on how to use the Horusec CLI tool which they install separately. Pure documentation-based skill with no code execution capabilities.
監査バージョン 2
安全Jan 10, 2026, 10:57 AM
This skill contains only documentation and configuration templates. No executable scripts, no network calls, and no direct filesystem access. The skill guides users on how to use the Horusec CLI tool which they install separately. Pure documentation-based skill with no code execution capabilities.
監査バージョン 1
安全Jan 10, 2026, 10:57 AM
This skill contains only documentation and configuration templates. No executable scripts, no network calls, and no direct filesystem access. The skill guides users on how to use the Horusec CLI tool which they install separately. Pure documentation-based skill with no code execution capabilities.