📦

監査履歴

when-gathering-requirements-use-interactive-planner - 8 監査

バージョン比較

監査済みバージョン間の機能と検出結果の変化(新しい順)。

バージョン日付結果レビュー項目前バージョンとの変化
v8 最新2026年7月6日 12:07 確認された検出結果なし0機能の変化なし
v7 2026年7月6日 12:07 確認された検出結果なし0外部コマンド
v6 2026年6月29日 19:53 確認された検出結果なし0 外部コマンド
v5 2026年1月17日 03:59 確認された検出結果なし0機能の変化なし
v4 2026年1月17日 03:59 確認された検出結果なし0外部コマンド
v3 2026年1月10日 13:23 確認された検出結果なし0機能の変化なし
v2 2026年1月10日 13:23 確認された検出結果なし0機能の変化なし
v1 2026年1月10日 13:23 確認された検出結果なし0基準

2026年7月6日 12:07

The single static finding is a false positive caused by a Markdown YAML code fence in SKILL.md, not executable Ruby or shell syntax. No prompt injection, data exfiltration, network access, or malicious intent was found in the reviewed skill content.

4
スキャンされたファイル
183
解析済み行数
1
レビュー項目
0
誤検知を無視

リスク要因

⚙️ 外部コマンド (1)
監査者: codex

2026年7月6日 12:07

The single static finding is a false positive caused by a Markdown YAML code fence in SKILL.md, not executable Ruby or shell syntax. No prompt injection, data exfiltration, network access, or malicious intent was found in the reviewed skill content.

4
スキャンされたファイル
183
解析済み行数
1
レビュー項目
0
誤検知を無視

リスク要因

⚙️ 外部コマンド (1)
監査者: codex

2026年6月29日 19:53

The static findings are false positives from Markdown formatting and ordinary descriptive text. The skill is documentation-only and contains no executable scripts, network calls, file operations, prompt injection text, or malicious intent.

4
スキャンされたファイル
183
解析済み行数
0
レビュー項目
3
誤検知を無視
静的解析の誤検知を無視 (3)

これらの静的マッチはセマンティックレビューで却下されたか、スキーマのみのトークンに一致したため、透明性のために表示されていますが、品質スコアには影響しません。

低
False Positive: Markdown Backticks Misidentified as Shell Execution
Verdict: FALSE_POSITIVE. The flagged backticks are Markdown code fences around a process diagram and YAML metadata, not executable Ruby or shell code.
The surrounding context is plain Markdown documentation. No command invocation syntax, interpreter directive, or execution path is present.
低
False Positive: Inline Memory Keys Misidentified as Shell Execution
Verdict: FALSE_POSITIVE. The flagged inline backticks list memory key names for requirements artifacts, not commands or dynamic execution.
The values are static documentation labels under a Memory Keys section. They are not passed to a shell or used by code.
低
False Positive: Descriptive Text Misidentified as Weak Cryptography
Verdict: FALSE_POSITIVE. The flagged weak cryptography matches come from ordinary words such as description and descriptive, not cryptographic code.
The lines contain human-readable requirement-gathering guidance. No hashing, encryption API, cipher configuration, or credential handling appears there.
この完了済み監査には、確認済みのセキュリティ検出事項は記録されていません。
監査者: codex

2026年1月17日 03:59

Pure documentation skill containing only Markdown, YAML, JSON, and Graphviz files. No executable code, network calls, file system access, or command execution. All 18 static findings are false positives: backticks are markdown formatting, version strings were misidentified as crypto algorithms, and URLs are metadata references.

5
スキャンされたファイル
377
解析済み行数
1
レビュー項目
0
誤検知を無視
監査者: claude

2026年1月17日 03:59

Pure documentation skill containing only Markdown, YAML, JSON, and Graphviz files. No executable code, network calls, file system access, or command execution. All 18 static findings are false positives: backticks are markdown formatting, version strings were misidentified as crypto algorithms, and URLs are metadata references.

5
スキャンされたファイル
377
解析済み行数
1
レビュー項目
0
誤検知を無視
監査者: claude

2026年1月10日 13:23

Pure documentation-based SOP with no executable code. Contains only YAML metadata, Markdown documentation, and a Graphviz diagram. No file system access, network calls, command execution, or code execution capabilities.

4
スキャンされたファイル
178
解析済み行数
0
レビュー項目
0
誤検知を無視
この完了済み監査には、確認済みのセキュリティ検出事項は記録されていません。
監査者: claude

2026年1月10日 13:23

Pure documentation-based SOP with no executable code. Contains only YAML metadata, Markdown documentation, and a Graphviz diagram. No file system access, network calls, command execution, or code execution capabilities.

4
スキャンされたファイル
178
解析済み行数
0
レビュー項目
0
誤検知を無視
この完了済み監査には、確認済みのセキュリティ検出事項は記録されていません。
監査者: claude

2026年1月10日 13:23

Pure documentation-based SOP with no executable code. Contains only YAML metadata, Markdown documentation, and a Graphviz diagram. No file system access, network calls, command execution, or code execution capabilities.

4
スキャンされたファイル
178
解析済み行数
0
レビュー項目
0
誤検知を無視
この完了済み監査には、確認済みのセキュリティ検出事項は記録されていません。
監査者: claude