監査履歴
sca-blackduck - 6 監査
監査バージョン 6
最新 中リスクJun 28, 2026, 06:18 AM
Static analysis found many severe-looking patterns, but most are documentation, policy terminology, or intentionally vulnerable examples for SCA education. The real concern is copyable CI guidance that uses network shell installers and handles Black Duck or GitHub secrets. No prompt injection attempt or confirmed malicious intent was found, so publication is acceptable with a security warning.
中リスクの問題 (3)
低リスクの問題 (3)
リスク要因
⚙️ 外部コマンド (7)
🌐 ネットワークアクセス (4)
🔑 環境変数 (5)
📁 ファイルシステムへのアクセス (4)
検出されたパターン
監査バージョン 5
低リスクJan 16, 2026, 04:14 PM
This skill consists entirely of documentation, configuration templates, and CI/CD workflow examples for legitimate security tooling. All 474 static findings are FALSE POSITVES. The flagged patterns appear in educational security documentation discussing attack patterns for detection purposes, not in malicious code. The skill promotes security best practices for dependency scanning.
リスク要因
⚙️ 外部コマンド (1)
🌐 ネットワークアクセス (1)
⚡ スクリプトを含む (1)
監査バージョン 4
低リスクJan 16, 2026, 04:14 PM
This skill consists entirely of documentation, configuration templates, and CI/CD workflow examples for legitimate security tooling. All 474 static findings are FALSE POSITVES. The flagged patterns appear in educational security documentation discussing attack patterns for detection purposes, not in malicious code. The skill promotes security best practices for dependency scanning.
リスク要因
⚙️ 外部コマンド (1)
🌐 ネットワークアクセス (1)
⚡ スクリプトを含む (1)
監査バージョン 3
安全Jan 10, 2026, 11:00 AM
This skill consists entirely of documentation, configuration templates, and CI/CD workflow examples. No executable scripts or code that could pose security risks were found. The skill provides legitimate security guidance for dependency scanning and license compliance.
監査バージョン 2
安全Jan 10, 2026, 11:00 AM
This skill consists entirely of documentation, configuration templates, and CI/CD workflow examples. No executable scripts or code that could pose security risks were found. The skill provides legitimate security guidance for dependency scanning and license compliance.
監査バージョン 1
安全Jan 10, 2026, 11:00 AM
This skill consists entirely of documentation, configuration templates, and CI/CD workflow examples. No executable scripts or code that could pose security risks were found. The skill provides legitimate security guidance for dependency scanning and license compliance.