監査履歴
gpt-series-reasoning-style - 6 監査
バージョン比較
監査済みバージョン間の機能と検出結果の変化(新しい順)。
2026年9月20日 03:25
All 91 static findings were adjudicated as false positives because they reference public metadata, documentation, fixed repository paths, or analysis heuristics rather than executed behavior. No prompt-injection text, data-exfiltration intent, or runtime command execution was evidenced in the reviewed files.
リスク要因
🌐 ネットワークアクセス (12)
📁 ファイルシステムへのアクセス (41)
2026年9月18日 05:39
All 65 static findings are false positives based on their cited snippets. They identify documentation examples, installation paths, Markdown syntax, a standard ignore entry, or entropy heuristics rather than executable malicious behavior; no prompt injection or data-exfiltration intent was evidenced.
リスク要因
⚙️ 外部コマンド (14)
🌐 ネットワークアクセス (6)
📁 ファイルシステムへのアクセス (26)
2026年9月17日 20:05
58 个静态命中均对应文档中的安装示例、代码围栏、正则字面量或纯文本熵启发式,未发现相应的运行时攻击行为。AGENTS.md 与 SKILL.md 仍包含控制代理加载顺序和执行规则的高风险提示注入式文本,安装前应由宿主策略和用户明确同意进行约束。
確認済みのセキュリティ上の懸念 (1)
リスク要因
⚙️ 外部コマンド (10)
🌐 ネットワークアクセス (6)
📁 ファイルシステムへのアクセス (26)
2026年9月16日 19:18
26 个静态发现均为误报:证据来自文档安装命令、Markdown 反引号、Python 文本匹配和普通文本熵启发式。未发现实际网络通信、危险命令执行、数据外传或提示注入证据。
リスク要因
🌐 ネットワークアクセス (3)
📁 ファイルシステムへのアクセス (4)
2026年9月12日 11:20
Most static alerts are false positives caused by defensive examples, readable Chinese prose, Markdown syntax, SVG paths, and documented installation locations. One high-risk behavior is confirmed: claim-check executes claims-file commands through shell=True, so hostile or insufficiently reviewed input can run arbitrary code. Static review was capped at 400/554 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
機能レビュー項目 (1)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
🌐 ネットワークアクセス (13)
⚙️ 外部コマンド (50)
📁 ファイルシステムへのアクセス (50)
2026年9月11日 21:27
The audit confirms one high-risk issue: scripts/claim-check.py executes commands from an untrusted claims file with shell=True. The other reviewed matches are false positives from documentation, defensive patterns, test harnesses, installer mechanics, or static-site content; the confirmed issue requires remediation before publication. Static review was capped at 400/536 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
機能レビュー項目 (1)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。