監査履歴
slidev - 6 監査
バージョン比較
監査済みバージョン間の機能と検出結果の変化(新しい順)。
2026年7月23日 07:16
Review found 105 static alerts, predominantly false positives caused by Markdown backticks, example URLs, Mermaid terminology, and local screen-recording documentation. PlantUML configuration can send diagram source to a remote server, and remote presenter mode can expose a network control surface. No prompt injection, covert upload, credential access, or malicious command construction was found.
確認済みのセキュリティ上の懸念 (1)
機能レビュー項目 (1)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
🌐 ネットワークアクセス (26)
⚙️ 外部コマンド (50)
2026年7月7日 20:39
All static findings were adjudicated as false positives caused by Markdown examples, sample URLs, Slidev feature names, and documentation tables. No evidence found of prompt injection, hidden exfiltration, unauthorized screen capture, or dynamic command execution in the skill content.
リスク要因
🌐 ネットワークアクセス (26)
⚙️ 外部コマンド (65)
2026年7月5日 02:23
The static alerts are false positives from Markdown examples, inline backticks, visible URLs, and documented Slidev features. I found no prompt injection, malware intent, hidden exfiltration, automatic command execution, or covert upload behavior in the reviewed files.
静的解析の誤検知を無視 (2)
これらの静的マッチはセマンティックレビューで却下されたか、スキーマのみのトークンに一致したため、透明性のために表示されていますが、品質スコアには影響しません。
リスク要因
🌐 ネットワークアクセス (24)
⚙️ 外部コマンド (63)
2026年7月5日 02:23
The static alerts are false positives from Markdown examples, inline backticks, visible URLs, and documented Slidev features. I found no prompt injection, malware intent, hidden exfiltration, automatic command execution, or covert upload behavior in the reviewed files.
静的解析の誤検知を無視 (2)
これらの静的マッチはセマンティックレビューで却下されたか、スキーマのみのトークンに一致したため、透明性のために表示されていますが、品質スコアには影響しません。
リスク要因
🌐 ネットワークアクセス (24)
⚙️ 外部コマンド (63)
2026年6月28日 09:11
Static analysis reported many high-risk patterns, but review shows the dominant hits are false positives from Markdown fences, inline backticks, file extensions, URLs, and documented CLI examples. No malicious intent or prompt injection was found. The skill is safe to publish with warnings because it documents user-triggered commands, remote sharing, public tunnels, screen recording, remote assets, and writable demo editors.
確認済みのセキュリティ上の懸念 (1)
機能レビュー項目 (2)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
静的解析の誤検知を無視 (3)
これらの静的マッチはセマンティックレビューで却下されたか、スキーマのみのトークンに一致したため、透明性のために表示されていますが、品質スコアには影響しません。
リスク要因
⚙️ 外部コマンド (6)
🌐 ネットワークアクセス (6)
2026年2月1日 08:41
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.