監査履歴
wecom-unified - 2 監査
バージョン比較
監査済みバージョン間の機能と検出結果の変化(新しい順)。
2026年8月18日 08:30
Most static findings are false positives caused by multilingual documentation, Markdown code formatting, example URLs, and defensive file-handling code. The audit identified one material workflow risk: the skill can automatically install an unpinned global npm package without user confirmation. No prompt-injection language, credential exfiltration, or concealed executable payload was found in the reviewed evidence.
確認済みのセキュリティ上の懸念 (1)
リスク要因
⚙️ 外部コマンド (50)
📁 ファイルシステムへのアクセス (8)
🌐 ネットワークアクセス (10)
🔑 環境変数 (1)
2026年8月18日 08:30
Most static findings are false positives caused by multilingual documentation, Markdown code formatting, example URLs, and defensive file-handling code. The audit identified one material workflow risk: the skill can automatically install an unpinned global npm package without user confirmation. No prompt-injection language, credential exfiltration, or concealed executable payload was found in the reviewed evidence.