監査履歴
product-launch-video - 2 監査
監査バージョン 2
最新 高リスクJun 30, 2026, 02:24 AM
Static analysis found many pattern matches. Most weak-crypto, backtick, and traversal alerts in Markdown and regex-heavy parsing code are false positives. However, the skill intentionally runs external commands, uses network capture and CDN assets, reads environment and hidden credentials, and writes generated project files across user-selected paths, so it should not be published without maintainer review and sandboxing.
高リスクの問題 (3)
中リスクの問題 (2)
低リスクの問題 (1)
リスク要因
📁 ファイルシステムへのアクセス (4)
🌐 ネットワークアクセス (3)
🔑 環境変数 (4)
検出されたパターン
監査バージョン 1
高リスクJun 27, 2026, 09:04 AM
The static findings are partly true positives and partly noisy matches from documentation. I found no evidence of malicious intent or prompt injection, but the skill executes local scripts, invokes external commands, reads provider credentials, captures URLs, and generates HTML that can execute remote or injected script. Publish should wait for remediation of the generated HTML injection and CDN execution risks.