Histórico de Auditoria
frontend-dev - 2 auditorias
Versão da auditoria 2
Mais recente Risco MédioMay 27, 2026, 06:26 PM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Fatores de risco
🌐 Acesso à rede (73)
⚙️ Comandos externos (841)
🔑 Variáveis de ambiente (51)
📁 Acesso ao sistema de arquivos (16)
⚡ Contém scripts (1)
Padrões Detectados
Versão da auditoria 1
Baixo RiscoApr 16, 2026, 06:14 AM
Static analysis flagged 1176 patterns with a risk score of 100/100, but evaluation confirms these are overwhelmingly false positives. High-severity 'weak cryptographic algorithm' findings in canvas-fonts/*.txt files are font Open Font License texts, not crypto code. 'Ruby/shell backtick execution' findings in markdown reference files are backtick-enclosed code examples in documentation. 'Windows SAM database' finding at templates/viewer.html:508 is the word 'CUSTOMIZE' containing the substring 'SAM'. regex.exec() in generator_template.js:133 is a standard JavaScript hex color parser. The skill is a legitimate frontend development tool with MiniMax API client scripts that properly use environment variables for API key management. Low risk after review.