監査履歴
pr - 8 監査
バージョン比較
監査済みバージョン間の機能と検出結果の変化(新しい順)。
| バージョン | 日付 | 結果 | レビュー項目 | 前バージョンとの変化 |
|---|---|---|---|---|
| v8 最新 | 2026年7月5日 06:25 | 1 確認済み | 2 | 機能の変化なし |
| v7 | 2026年7月5日 06:25 | 1 確認済み | 2 | 機能の変化なし |
| v6 | 2026年6月28日 22:55 | 確認された検出結果なし | 1 | 機能の変化なし |
| v5 | 2026年1月16日 21:19 | 確認された検出結果なし | 0 | 機能の変化なし |
| v4 | 2026年1月16日 21:19 | 確認された検出結果なし | 0 | ネットワークアクセス外部コマンド |
| v3 | 2026年1月10日 12:15 | 確認された検出結果なし | 0 | 機能の変化なし |
| v2 | 2026年1月10日 12:15 | 確認された検出結果なし | 0 | 機能の変化なし |
| v1 | 2026年1月10日 12:15 | 確認された検出結果なし | 0 | 基準 |
2026年7月5日 06:25
Most static findings are false positives caused by Markdown backticks, examples, and documentation links. Two external-command findings are confirmed because the skill directs git and GitHub CLI commands that can commit, push, and create pull requests. One semantic issue notes that broad git staging can publish unrelated or sensitive files.
確認済みのセキュリティ上の懸念 (1)
機能レビュー項目 (2)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (31)
🌐 ネットワークアクセス (4)
2026年7月5日 06:25
Most static findings are false positives caused by Markdown backticks, examples, and documentation links. Two external-command findings are confirmed because the skill directs git and GitHub CLI commands that can commit, push, and create pull requests. One semantic issue notes that broad git staging can publish unrelated or sensitive files.
確認済みのセキュリティ上の懸念 (1)
機能レビュー項目 (2)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (31)
🌐 ネットワークアクセス (4)
2026年6月28日 22:55
Static analysis reported many backtick, URL, C2, weak crypto, and reconnaissance patterns, but review shows most are false positives from Markdown examples and Japanese text. The confirmed risk is that the skill guides agents to run git and gh commands that can stage files, commit, push branches, and create pull requests. No evidence found of malware, prompt injection, credential exfiltration, or hidden command execution.
機能レビュー項目 (1)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
静的解析の誤検知を無視 (3)
これらの静的マッチはセマンティックレビューで却下されたか、スキーマのみのトークンに一致したため、透明性のために表示されていますが、品質スコアには影響しません。
リスク要因
⚙️ 外部コマンド (3)
🌐 ネットワークアクセス (4)
検出されたパターン
2026年1月16日 21:19
This skill consists of a single SKILL.md documentation file with no executable code. All 51 static findings are false positives: markdown code blocks were misidentified as backtick execution, workflow strings like 'action-id' and '{AC2}' as C2 keywords, and GitHub URLs as hardcoded network endpoints. The file contains only documentation describing PR creation workflows.
リスク要因
🌐 ネットワークアクセス (4)
⚙️ 外部コマンド (32)
2026年1月16日 21:19
This skill consists of a single SKILL.md documentation file with no executable code. All 51 static findings are false positives: markdown code blocks were misidentified as backtick execution, workflow strings like 'action-id' and '{AC2}' as C2 keywords, and GitHub URLs as hardcoded network endpoints. The file contains only documentation describing PR creation workflows.
リスク要因
🌐 ネットワークアクセス (4)
⚙️ 外部コマンド (32)
2026年1月10日 12:15
This skill consists of a single SKILL.md documentation file with no executable code. The file describes PR creation workflows and templates but contains no scripts, network calls, file operations, or command execution capabilities. All git/gh commands mentioned are documentation only, not actual code.
2026年1月10日 12:15
This skill consists of a single SKILL.md documentation file with no executable code. The file describes PR creation workflows and templates but contains no scripts, network calls, file operations, or command execution capabilities. All git/gh commands mentioned are documentation only, not actual code.
2026年1月10日 12:15
This skill consists of a single SKILL.md documentation file with no executable code. The file describes PR creation workflows and templates but contains no scripts, network calls, file operations, or command execution capabilities. All git/gh commands mentioned are documentation only, not actual code.