📦

監査履歴

personwise-sop-process-training - 1 監査

2026年8月5日 18:38

The 142 static alerts are false positives caused by Markdown backticks, defensive installer operations, and signed high-entropy metadata. The skill still presents high external-code risk because it installs an opaque CLI with native signature enforcement disabled, and it uploads selected documents to PersonWise.

6
スキャンされたファイル
648
解析済み行数
5
レビュー項目
0
誤検知を無視

確認済みのセキュリティ上の懸念 (2)

高
Opaque External CLI Installation
The skill directs installation and execution of a remotely downloaded PersonWise binary. Hash pinning protects integrity, but the binary behavior is not auditable from this skill, and native signature enforcement is disabled.
The workflow explicitly installs a remote executable and both installers show disabled native signature requirements. The included files do not provide the executable source for behavioral review.
中
Source Documents Uploaded to External Service
The workflow uploads user-selected SOP and policy files to PersonWise for processing. This can expose confidential operational material to a third-party service.
The documented source add command uploads exact local paths, and the surrounding instructions discuss upload grants and source processing. The transfer is an intended workflow step.
監査者: codex