監査履歴
sheet-to-report - 3 監査
バージョン比較
監査済みバージョン間の機能と検出結果の変化(新しい順)。
2026年9月21日 06:59
All 400 catalogued static findings were adjudicated as false positives after targeted source review. Obfuscation alerts map to readable Chinese text, generated HTML or CSS, and ordinary collection syntax; local command and filesystem operations use bounded arguments and generated directories. No prompt injection or exfiltration intent was found, but 386 scanner matches omitted by the static cap still require cataloguing before automatic publication. Static review was capped at 400/786 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
確認済みのセキュリティ上の懸念 (1)
リスク要因
🌐 ネットワークアクセス (42)
⚙️ 外部コマンド (50)
⚡ スクリプトを含む (50)
📁 ファイルシステムへのアクセス (43)
🔑 環境変数 (11)
2026年9月16日 07:50
All 400 presented static findings are false positives caused by documentation, CJK text, generated HTML, validation helpers, or bounded local report tooling. External commands use fixed argument arrays without shell interpolation, and no prompt injection, secret collection, data exfiltration, or covert network behavior was found. Static review was capped at 400/728 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
リスク要因
🌐 ネットワークアクセス (35)
⚙️ 外部コマンド (50)
⚡ スクリプトを含む (50)
📁 ファイルシステムへのアクセス (43)
🔑 環境変数 (11)
2026年9月11日 12:39
All 400 presented static findings were reviewed and judged false positives: they describe normal local report generation, validation, rendering, documentation, or repository hygiene. No prompt injection, credential exfiltration, or malicious intent was evidenced in the reviewed locations; 318 repeated or lower-priority matches remain outside the presented catalog, and no net-new semantic finding was identified. Static review was capped at 400/718 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.