Audit-Verlauf
setup-pre-commit - 5 Audits
Versionsvergleich
Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.
| Version | Datum | Ergebnis | Prüfelemente | Änderung ggü. vorheriger |
|---|---|---|---|---|
| v5 Neueste | 2026年7月23日 16:47 | 1 bestätigt | 0 | Keine Änderung der Fähigkeiten |
| v4 | 2026年7月8日 07:03 | 2 bestätigt | 14 | Keine Änderung der Fähigkeiten |
| v3 | 2026年7月5日 20:18 | 1 bestätigt | 0 | Dateisystemzugriff |
| v2 | 2026年6月30日 07:36 | 2 bestätigt | 0 | Dateisystemzugriff |
| v1 | 2026年6月12日 09:35 | Keine bestätigten Befunde | 1 | Ausgangsbasis |
2026年7月23日 16:47
All 22 static findings are false positives caused by Markdown backticks and fenced examples, not Ruby backtick execution or injectable command construction. One semantic risk remains: the workflow instructs the agent to stage every changed file, which can include unrelated or sensitive work.
Bestätigte Sicherheitsbedenken (1)
Risikofaktoren
⚙️ Externe Befehle (22)
2026年7月8日 07:03
Most static findings are Markdown backticks or fenced examples, not Ruby backtick execution. The skill still directs agents to install packages, run npx and npm commands, create a Git hook, and commit changed files. No prompt injection or credential exfiltration intent was found.
Bestätigte Sicherheitsbedenken (2)
Elemente der Fähigkeitsprüfung (14)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.
Risikofaktoren
⚙️ Externe Befehle (22)
2026年7月5日 20:18
No prompt injection or hidden malicious intent was found in SKILL.md. The static findings are false positives from Markdown backticks and standard command examples, while one semantic risk remains for staging all changed files before commit.
Bestätigte Sicherheitsbedenken (1)
Risikofaktoren
⚙️ Externe Befehle (22)
2026年6月30日 07:36
Static analysis flagged many command references and one weak-cryptography hit. The command references are true positives because the skill instructs agents to install packages, run npx, run project scripts, edit hook files, and commit changes; these are legitimate for this skill but require user review. The weak-cryptography finding at SKILL.md:3 is a false positive, and I found no evidence of malware, data exfiltration, network calls, credential access, or prompt injection.
Bestätigte Sicherheitsbedenken (2)
Statische falsch positive Treffer ignoriert (1)
Diese statischen Treffer wurden durch semantische Prüfung verworfen oder entsprachen reinen Schema-Tokens; daher werden sie aus Transparenzgründen angezeigt, beeinflussen jedoch nicht die Qualitätsbewertung.
Risikofaktoren
⚙️ Externe Befehle (3)
📁 Dateisystemzugriff (3)
Erkannte Muster
2026年6月12日 09:35
The SKILL.md file contains documentation for setting up pre-commit hooks using Husky, lint-staged, and Prettier. All detected 'external_commands' are legitimate CLI commands (npm, npx, husky, prettier) documented as setup instructions. The 'weak cryptographic algorithm' finding at line 3 is a false positive — no cryptographic code exists in the file. The skill is a standard development tool setup guide with no malicious intent.
Elemente der Fähigkeitsprüfung (1)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.