🔍

감사 이력

get-available-resources - 5 감사들

감사 버전 5

최신 낮은 위험

Jan 17, 2026, 07:36 AM

The skill is safe to publish. All 50 static findings are false positives. The skill performs legitimate system resource detection using subprocess calls to standard system utilities (nvidia-smi, rocm-smi, sysctl, system_profiler) for GPU/CPU detection. All subprocess commands use hardcoded arguments in list format, preventing shell injection. The __import__ usage is for importing the standard datetime module. Markdown backticks triggered false positives for shell execution. 'Weak cryptographic algorithm' findings are scanner errors on non-cryptographic code.

4
스캔된 파일
1,073
분석된 줄 수
4
발견 사항
claude
감사자
낮은 위험 문제 (1)
JSON file output to disk
Skill writes a JSON file to disk (.claude_resources.json) containing system resource information. This is expected behavior but users should be aware.

감사 버전 4

낮은 위험

Jan 17, 2026, 07:36 AM

The skill is safe to publish. All 50 static findings are false positives. The skill performs legitimate system resource detection using subprocess calls to standard system utilities (nvidia-smi, rocm-smi, sysctl, system_profiler) for GPU/CPU detection. All subprocess commands use hardcoded arguments in list format, preventing shell injection. The __import__ usage is for importing the standard datetime module. Markdown backticks triggered false positives for shell execution. 'Weak cryptographic algorithm' findings are scanner errors on non-cryptographic code.

4
스캔된 파일
1,073
분석된 줄 수
4
발견 사항
claude
감사자
낮은 위험 문제 (1)
JSON file output to disk
Skill writes a JSON file to disk (.claude_resources.json) containing system resource information. This is expected behavior but users should be aware.

감사 버전 3

낮은 위험

Jan 17, 2026, 07:36 AM

The skill is safe to publish. All 50 static findings are false positives. The skill performs legitimate system resource detection using subprocess calls to standard system utilities (nvidia-smi, rocm-smi, sysctl, system_profiler) for GPU/CPU detection. All subprocess commands use hardcoded arguments in list format, preventing shell injection. The __import__ usage is for importing the standard datetime module. Markdown backticks triggered false positives for shell execution. 'Weak cryptographic algorithm' findings are scanner errors on non-cryptographic code.

4
스캔된 파일
1,073
분석된 줄 수
3
발견 사항
claude
감사자
보안 문제를 찾지 못했습니다

감사 버전 2

안전

Jan 12, 2026, 04:13 PM

All static findings are false positives. The skill performs legitimate system resource detection using subprocess calls to standard system utilities (nvidia-smi, rocm-smi, system_profiler) for GPU/CPU detection. All commands use hardcoded arguments in list format, preventing shell injection. No user input is processed. The skill outputs a JSON file with resource information for informed computational decisions.

2
스캔된 파일
679
분석된 줄 수
3
발견 사항
claude
감사자
보안 문제를 찾지 못했습니다

감사 버전 1

낮은 위험

Jan 4, 2026, 04:32 PM

The skill only queries local system resources through psutil and system utilities. It writes a JSON file to the current working directory. No network access, credential harvesting, or persistence mechanisms detected. External commands are hardcoded subprocess calls to legitimate system tools (nvidia-smi, rocm-smi, sysctl).

5
스캔된 파일
913
분석된 줄 수
3
발견 사항
claude
감사자
보안 문제를 찾지 못했습니다