監査履歴
agy-worker - 8 監査
バージョン比較
監査済みバージョン間の機能と検出結果の変化(新しい順)。
| バージョン | 日付 | 結果 | レビュー項目 | 前バージョンとの変化 |
|---|---|---|---|---|
| v8 最新 | 2026年9月20日 21:08 | 7 確認済み | 50 | 機能の変化なし |
| v7 | 2026年9月19日 10:47 | 3 確認済み | 12 | 機能の変化なし |
| v6 | 2026年9月12日 18:26 | 確認された検出結果なし | 12 | 機能の変化なし |
| v5 | 2026年9月6日 12:11 | 1 確認済み | 4 | 機能の変化なし |
| v4 | 2026年8月31日 11:24 | 1 確認済み | 4 | 機能の変化なし |
| v3 | 2026年8月31日 11:24 | 1 確認済み | 4 | 機能の変化なし |
| v2 | 2026年8月29日 19:38 | 1 確認済み | 0 | 機能の変化なし |
| v1 | 2026年8月29日 10:25 | 4 確認済み | 4 | 基準 |
2026年9月20日 21:08
Most static matches are benign implementation, validation, documentation, schema, or control-character checks. Confirmed risks include provider and verifier execution, environment inheritance, keychain handling, settings access, and non-sandboxed provider authority. Static review was capped at 400/991 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
確認済みのセキュリティ上の懸念 (7)
機能レビュー項目 (50)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (50)
🌐 ネットワークアクセス (43)
📁 ファイルシステムへのアクセス (50)
⚡ スクリプトを含む (22)
🔑 環境変数 (15)
2026年9月19日 10:47
The review confirmed intentional high-impact capabilities: external provider execution, repository-content transmission, verifier command execution, and limited private configuration access. Most static matches are false positives from defensive validation, documentation, compact schemas, or fixed local commands. Default session mode lacks host containment, and 589 lower-priority static matches remain outside the supplied adjudication set. Static review was capped at 400/989 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
確認済みのセキュリティ上の懸念 (3)
機能レビュー項目 (12)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (50)
🌐 ネットワークアクセス (43)
📁 ファイルシステムへのアクセス (50)
⚡ スクリプトを含む (22)
🔑 環境変数 (15)
2026年9月12日 18:26
Most reviewed matches are false positives from documentation, schemas, validation literals, fixed Git commands, and type annotations. Confirmed risks are provider execution, approved verifier execution, legacy shell verification, selected environment forwarding, and opt-in access to Antigravity user settings. No prompt injection or exfiltration intent was found, but 565 capped static matches still require manual review before automatic publication. Static review was capped at 400/965 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
機能レビュー項目 (12)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (50)
📁 ファイルシステムへのアクセス (50)
⚡ スクリプトを含む (22)
🌐 ネットワークアクセス (38)
🔑 環境変数 (15)
2026年9月6日 12:11
All 400 presented static findings were adjudicated individually. Most matches are benign validation, documentation, schema, or bounded orchestration patterns, but account configuration access and legacy shell verification are confirmed risks. The skill also explicitly allows provider execution with normal filesystem and network authority in session mode, so operators must treat it as a delegation tool rather than a sandbox. Static review was capped at 400/962 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
確認済みのセキュリティ上の懸念 (1)
機能レビュー項目 (4)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (50)
📁 ファイルシステムへのアクセス (50)
⚡ スクリプトを含む (22)
🌐 ネットワークアクセス (37)
🔑 環境変数 (15)
2026年8月31日 11:24
Of 400 static findings, 396 are lexical false positives from schema punctuation, defensive validation, documentation, or bounded local tooling. Confirmed risks are the external AGY launch, caller-selected verifier execution, and two legacy shell-verification paths. Default provider dispatch also creates a documented high-impact repository disclosure risk unless operators use a narrow approved scope. Static review was capped at 400/889 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
確認済みのセキュリティ上の懸念 (1)
機能レビュー項目 (4)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (50)
📁 ファイルシステムへのアクセス (50)
⚡ スクリプトを含む (20)
🌐 ネットワークアクセス (47)
🔑 環境変数 (14)
2026年8月31日 11:24
Of 400 static findings, 396 are lexical false positives from schema punctuation, defensive validation, documentation, or bounded local tooling. Confirmed risks are the external AGY launch, caller-selected verifier execution, and two legacy shell-verification paths. Default provider dispatch also creates a documented high-impact repository disclosure risk unless operators use a narrow approved scope. Static review was capped at 400/889 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
確認済みのセキュリティ上の懸念 (1)
機能レビュー項目 (4)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (50)
📁 ファイルシステムへのアクセス (50)
⚡ スクリプトを含む (20)
🌐 ネットワークアクセス (47)
🔑 環境変数 (14)
2026年8月29日 19:38
The 400 presented static matches are false positives caused by documentation syntax, compact JSON, defensive validation, and declared repository orchestration. One medium confidentiality risk remains: approved repository content is transmitted to the external agy provider, and 366 capped static matches still require manual review before automatic publication. Static review was capped at 400/766 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
確認済みのセキュリティ上の懸念 (1)
リスク要因
⚡ スクリプトを含む (18)
⚙️ 外部コマンド (50)
📁 ファイルシステムへのアクセス (50)
🌐 ネットワークアクセス (33)
2026年8月29日 10:25
Most static matches are false positives caused by Markdown formatting, minified JSON Schemas, defensive control-character checks, and fixed argv subprocesses. Confirmed risks include external AGY dispatch, unrestricted driver-supplied Bash verification, and inherited environment exposure. The skill also embeds system-style persona prompts and intentionally transmits approved repository content to Google or Gemini services. Static review was capped at 400/724 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
確認済みのセキュリティ上の懸念 (4)
機能レビュー項目 (4)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。