Audit-Verlauf
using-git-worktrees - 9 Audits
Versionsvergleich
Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.
| Version | Datum | Ergebnis | Prüfelemente | Änderung ggü. vorheriger |
|---|---|---|---|---|
| v9 Neueste | 2026年7月23日 15:48 | 2 bestätigt | 0 | Keine Änderung der Fähigkeiten |
| v8 | 2026年7月10日 14:26 | 3 bestätigt | 0 | Keine Änderung der Fähigkeiten |
| v7 | 2026年7月5日 08:40 | 2 bestätigt | 0 | Keine Änderung der Fähigkeiten |
| v6 | 2026年6月29日 16:00 | Keine bestätigten Befunde | 4 | Keine Änderung der Fähigkeiten |
| v5 | 2026年1月17日 03:24 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v4 | 2026年1月17日 03:24 | Keine bestätigten Befunde | 0 | DateisystemzugriffExterne Befehle |
| v3 | 2026年1月7日 01:36 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v2 | 2026年1月7日 01:36 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v1 | 2026年1月7日 01:36 | Keine bestätigten Befunde | 0 | Ausgangsbasis |
2026年7月23日 15:48
The static findings are false positives caused by Markdown formatting, documented Git commands, dedicated worktree paths, and standard error redirection. However, the skill automatically runs repository-controlled setup and test commands, and it may commit a .gitignore change without explicit approval.
Bestätigte Sicherheitsbedenken (2)
Risikofaktoren
⚙️ Externe Befehle (26)
📁 Dateisystemzugriff (13)
2026年7月10日 14:26
The 39 static findings are false positives caused by Markdown formatting, intended Git operations, documented worktree paths, and standard /dev/null redirection. Semantic review found automatic project code execution, an unapproved commit workflow, and a quoted-home-path defect.
Bestätigte Sicherheitsbedenken (3)
Risikofaktoren
⚙️ Externe Befehle (26)
📁 Dateisystemzugriff (13)
2026年7月5日 08:40
Most static findings are false positives caused by Markdown fences, documented worktree paths, and stderr redirects. I found no prompt injection or data exfiltration intent. The main risks are automatic project command execution and an automatic commit step.
Bestätigte Sicherheitsbedenken (2)
Risikofaktoren
⚙️ Externe Befehle (25)
📁 Dateisystemzugriff (12)
2026年6月29日 16:00
Static command execution findings are true positives because the skill instructs agents to run Git, package manager, build, and test commands. The hidden file and weak cryptography findings are false positives or low-risk context; no malicious intent, network exfiltration, credential access, or prompt injection was found.
Elemente der Fähigkeitsprüfung (4)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.
Statische falsch positive Treffer ignoriert (1)
Diese statischen Treffer wurden durch semantische Prüfung verworfen oder entsprachen reinen Schema-Tokens; daher werden sie aus Transparenzgründen angezeigt, beeinflussen jedoch nicht die Qualitätsbewertung.
Risikofaktoren
⚙️ Externe Befehle (8)
📁 Dateisystemzugriff (6)
Erkannte Muster
2026年1月17日 03:24
Documentation-only skill providing git worktree management instructions. All 47 static findings are false positives: JSON metadata field names were misidentified as cryptographic patterns, bash code examples in documentation blocks were flagged as shell execution, and standard git directory patterns were marked as hidden file access. No executable code, network calls, or sensitive data exposure exists in this skill.
Risikofaktoren
📁 Dateisystemzugriff (12)
⚙️ Externe Befehle (25)
2026年1月17日 03:24
Documentation-only skill providing git worktree management instructions. All 47 static findings are false positives: JSON metadata field names were misidentified as cryptographic patterns, bash code examples in documentation blocks were flagged as shell execution, and standard git directory patterns were marked as hidden file access. No executable code, network calls, or sensitive data exposure exists in this skill.
Risikofaktoren
📁 Dateisystemzugriff (12)
⚙️ Externe Befehle (25)
2026年1月7日 01:36
Prompt-based skill with pure instructions. Uses standard git commands for worktree creation. No executable code, no network access, no sensitive data exposure. All capabilities align with stated purpose of creating isolated git workspaces.
2026年1月7日 01:36
Prompt-based skill with pure instructions. Uses standard git commands for worktree creation. No executable code, no network access, no sensitive data exposure. All capabilities align with stated purpose of creating isolated git workspaces.
2026年1月7日 01:36
Prompt-based skill with pure instructions. Uses standard git commands for worktree creation. No executable code, no network access, no sensitive data exposure. All capabilities align with stated purpose of creating isolated git workspaces.