監査履歴
pptx - 9 監査
バージョン比較
監査済みバージョン間の機能と検出結果の変化(新しい順)。
| バージョン | 日付 | 結果 | レビュー項目 | 前バージョンとの変化 |
|---|---|---|---|---|
| v9 最新 | 2026年7月21日 07:58 | 確認された検出結果なし | 4 | 機能の変化なし |
| v8 | 2026年7月9日 14:09 | 1 確認済み | 10 | 機能の変化なし |
| v7 | 2026年7月6日 17:52 | 確認された検出結果なし | 31 | 機能の変化なし |
| v6 | 2026年7月6日 17:52 | 確認された検出結果なし | 31 | スクリプトを含む |
| v5 | 2026年6月30日 06:10 | 4 確認済み | 0 | スクリプトを含む環境変数 |
| v4 | 2026年1月17日 07:31 | 確認された検出結果なし | 0 | 機能の変化なし |
| v3 | 2026年1月17日 07:31 | 確認された検出結果なし | 0 | 機能の変化なし |
| v2 | 2026年1月12日 17:07 | 確認された検出結果なし | 0 | ネットワークアクセス スクリプトを含む |
| v1 | 2026年1月4日 16:19 | 確認された検出結果なし | 0 | 基準 |
2026年7月21日 07:58
Most static matches are benign OOXML namespaces, documentation, template literals, and ordinary local document-processing operations. Four archive extraction calls are confirmed high-risk because they use extractall() on supplied Office archives without member-path validation. No prompt-injection, credential-exfiltration, or unauthorized network intent was found in the reviewed context. Static review was capped at 400/508 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
機能レビュー項目 (4)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (50)
🌐 ネットワークアクセス (50)
📁 ファイルシステムへのアクセス (50)
2026年7月9日 14:09
Most static findings are false positives from OOXML namespace URLs, Markdown inline code, CSS color values, and JavaScript template literals. Confirmed risks are unsafe ZIP extraction of Office archives, privileged dependency installation instructions, and external hosted service steering. Fixed-argument subprocess calls do not show shell injection, but document converters should still be isolated for untrusted files.
確認済みのセキュリティ上の懸念 (1)
機能レビュー項目 (10)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (126)
🌐 ネットワークアクセス (206)
📁 ファイルシステムへのアクセス (54)
2026年7月6日 17:52
The audit confirms real risk in unsafe ZIP archive extraction, selected external converter execution, and privileged or environment-modifying install guidance. Most other static hits are false positives from OOXML namespace URLs, schema references, Markdown formatting, JavaScript template literals, or validation text. No prompt injection or data-exfiltration intent was found in the reviewed skill files.
機能レビュー項目 (31)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (126)
🌐 ネットワークアクセス (206)
📁 ファイルシステムへのアクセス (54)
2026年7月6日 17:52
The audit confirms real risk in unsafe ZIP archive extraction, selected external converter execution, and privileged or environment-modifying install guidance. Most other static hits are false positives from OOXML namespace URLs, schema references, Markdown formatting, JavaScript template literals, or validation text. No prompt injection or data-exfiltration intent was found in the reviewed skill files.
機能レビュー項目 (31)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (126)
🌐 ネットワークアクセス (206)
📁 ファイルシステムへのアクセス (54)
2026年6月30日 06:10
Static analysis reported many severe patterns, but most high blocker hits in schemas and markdown are false positives from OOXML vocabulary, examples, and dependency instructions. The confirmed risk is operational: helper scripts extract Office ZIP archives and run local converters, so this community skill should not be published without sandboxing guidance or safer extraction fixes.
確認済みのセキュリティ上の懸念 (4)
静的解析の誤検知を無視 (3)
これらの静的マッチはセマンティックレビューで却下されたか、スキーマのみのトークンに一致したため、透明性のために表示されていますが、品質スコアには影響しません。
リスク要因
⚙️ 外部コマンド (4)
📁 ファイルシステムへのアクセス (3)
🔑 環境変数 (2)
検出されたパターン
2026年1月17日 07:31
The pptx skill is a legitimate presentation toolkit for PowerPoint manipulation. All 1211 static findings are false positives. The scanner misinterpreted markdown documentation code blocks as Ruby backticks, standard OOXML schema definitions as cryptographic weaknesses and C2 keywords, and legitimate file operations as system reconnaissance. No actual security risks exist.
リスク要因
🌐 ネットワークアクセス (2)
📁 ファイルシステムへのアクセス (2)
2026年1月17日 07:31
The pptx skill is a legitimate presentation toolkit for PowerPoint manipulation. All 1211 static findings are false positives. The scanner misinterpreted markdown documentation code blocks as Ruby backticks, standard OOXML schema definitions as cryptographic weaknesses and C2 keywords, and legitimate file operations as system reconnaissance. No actual security risks exist.
リスク要因
🌐 ネットワークアクセス (2)
📁 ファイルシステムへのアクセス (2)
2026年1月12日 17:07
The pptx skill is a legitimate presentation toolkit with no actual security risks. All 1166 static findings are false positives from standard document processing operations, XML schema validation, and legitimate office automation tools.
リスク要因
🌐 ネットワークアクセス (2)
📁 ファイルシステムへのアクセス (2)
2026年1月4日 16:19
No credential access, environment harvesting, or network exfiltration detected. Subprocess calls limited to local document conversion tools (soffice, pdftoppm). All file operations scoped to user-specified PPTX files. Uses defusedxml for secure XML parsing.