監査履歴
app-store-screenshots - 6 監査
バージョン比較
監査済みバージョン間の機能と検出結果の変化(新しい順)。
2026年7月9日 07:31
The high screen-capture detections are false positives: the skill asks for local app screenshot files and uses local DOM capture for export. The external-command detections are Markdown setup examples, inline code, or TypeScript snippets with fixed commands and no dynamic execution path. Manual review of mockup.png found a normal phone-frame PNG asset.
リスク要因
⚙️ 外部コマンド (45)
2026年7月9日 07:31
The high screen-capture detections are false positives: the skill asks for local app screenshot files and uses local DOM capture for export. The external-command detections are Markdown setup examples, inline code, or TypeScript snippets with fixed commands and no dynamic execution path. Manual review of mockup.png found a normal phone-frame PNG asset.
リスク要因
⚙️ 外部コマンド (45)
2026年7月5日 20:53
Most static findings are false positives caused by Markdown code fences, inline code, and TSX template literals. The only confirmed issue is the setup block that tells an agent to run package-manager commands, which is legitimate but can download dependencies and change the workspace. The screen-capture, system-reconnaissance, and binary-file findings were not supported by the reviewed context.
機能レビュー項目 (1)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
静的解析の誤検知を無視 (3)
これらの静的マッチはセマンティックレビューで却下されたか、スキーマのみのトークンに一致したため、透明性のために表示されていますが、品質スコアには影響しません。
リスク要因
⚙️ 外部コマンド (45)
2026年7月5日 20:53
Most static findings are false positives caused by Markdown code fences, inline code, and TSX template literals. The only confirmed issue is the setup block that tells an agent to run package-manager commands, which is legitimate but can download dependencies and change the workspace. The screen-capture, system-reconnaissance, and binary-file findings were not supported by the reviewed context.
機能レビュー項目 (1)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
静的解析の誤検知を無視 (3)
これらの静的マッチはセマンティックレビューで却下されたか、スキーマのみのトークンに一致したため、透明性のために表示されていますが、品質スコアには影響しません。
リスク要因
⚙️ 外部コマンド (45)
2026年6月30日 10:45
Static analysis reported many high-risk patterns, but review shows most are Markdown false positives from inline code, screenshot terminology, and words that matched cryptography heuristics. The confirmed risk is legitimate operational behavior: package installation, project scaffolding, filesystem writes, and local image export. No evidence found of prompt injection, credential access, obfuscation, malicious network exfiltration, or unauthorized screenshot upload.
確認済みのセキュリティ上の懸念 (2)
静的解析の誤検知を無視 (2)
これらの静的マッチはセマンティックレビューで却下されたか、スキーマのみのトークンに一致したため、透明性のために表示されていますが、品質スコアには影響しません。
リスク要因
⚙️ 外部コマンド (1)
🌐 ネットワークアクセス (2)
📁 ファイルシステムへのアクセス (2)
検出されたパターン
2026年3月11日 00:14
Static analysis detected 75 potential issues across 335 lines, all of which are false positives upon review. The findings consist of bash command examples in markdown code blocks (instructional documentation), legitimate use of html-to-image library for screenshot generation (core functionality), and MD5 hashes used for content integrity verification. No executable code, no network exfiltration, no credential access, and no malicious intent detected. This is a legitimate skill for generating App Store marketing assets.