История аудитов
context-save - 8 аудиты
Сравнение версий
Изменения возможностей и находок между проверенными версиями, сначала новые.
| Версия | Дата | Результат | Пункты проверки | Изменение к предыдущей |
|---|---|---|---|---|
| v8 Последняя | 2026年7月5日 06:50 | 1 подтверждено | 0 | Возможности не изменились |
| v7 | 2026年7月5日 06:50 | 1 подтверждено | 0 | Внешние команды Доступ к файловой системе |
| v6 | 2026年6月28日 22:02 | Подтверждённых находок нет | 1 | Доступ к файловой системе Внешние команды |
| v5 | 2026年1月16日 20:31 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v4 | 2026年1月16日 20:31 | Подтверждённых находок нет | 0 | Внешние команды |
| v3 | 2026年1月10日 12:13 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v2 | 2026年1月10日 12:13 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v1 | 2026年1月10日 12:13 | Подтверждённых находок нет | 0 | Базовая |
2026年7月5日 06:50
Static external-command, system-reconnaissance, and obfuscation alerts are false positives from Markdown formatting, examples, and readable Chinese prose. No executable shell, Ruby, network, or reconnaissance behavior was found in SKILL.md. A medium-risk issue remains because session notes may persist sensitive context without redaction guidance.
Подтверждённые проблемы безопасности (1)
Факторы риска
2026年7月5日 06:50
Static external-command, system-reconnaissance, and obfuscation alerts are false positives from Markdown formatting, examples, and readable Chinese prose. No executable shell, Ruby, network, or reconnaissance behavior was found in SKILL.md. A medium-risk issue remains because session notes may persist sensitive context without redaction guidance.
Подтверждённые проблемы безопасности (1)
Факторы риска
2026年6月28日 22:02
Static command-execution, weak-crypto, reconnaissance, and entropy findings are false positives caused by Markdown backticks, readable Chinese prose, and example text. The confirmed risk is that the skill directs agents to persist session summaries into repository files, which can accidentally retain secrets or proprietary context.
Пункты проверки возможностей (1)
Это реальные локальные возможности, которые могут ожидаться для этого навыка, поэтому они требуют проверки, но не считаются подтверждённым вредоносным поведением.
Статические ложные срабатывания проигнорированы (4)
Эти статические совпадения были отклонены семантической проверкой или совпадали только со схемными токенами, поэтому они показываются для прозрачности, но не влияют на оценку качества.
Факторы риска
📁 Доступ к файловой системе (3)
2026年1月16日 20:31
This is a prompt-based skill with no executable code. SKILL.md contains only natural language instructions for generating markdown session summaries. No file system access, network calls, or command execution capabilities exist in the skill itself. The static analyzer produced false positives by misinterpreting Chinese text and markdown formatting as security vulnerabilities. All findings are dismissed as false positives.
Факторы риска
2026年1月16日 20:31
This is a prompt-based skill with no executable code. SKILL.md contains only natural language instructions for generating markdown session summaries. No file system access, network calls, or command execution capabilities exist in the skill itself. The static analyzer produced false positives by misinterpreting Chinese text and markdown formatting as security vulnerabilities. All findings are dismissed as false positives.
Факторы риска
2026年1月10日 12:13
This is a prompt-based skill with no executable code. It provides instructions for generating markdown session summaries. No file system access, network calls, or command execution capabilities detected. The behavior matches the stated purpose exactly.
2026年1月10日 12:13
This is a prompt-based skill with no executable code. It provides instructions for generating markdown session summaries. No file system access, network calls, or command execution capabilities detected. The behavior matches the stated purpose exactly.
2026年1月10日 12:13
This is a prompt-based skill with no executable code. It provides instructions for generating markdown session summaries. No file system access, network calls, or command execution capabilities detected. The behavior matches the stated purpose exactly.