Навыки architecture-reference История аудитов
📦

История аудитов

architecture-reference - 5 аудиты

Сравнение версий

Изменения возможностей и находок между проверенными версиями, сначала новые.

ВерсияДатаРезультатПункты проверкиИзменение к предыдущей
v5 Последняя20 июл. 2026 г., 17:14 Подтверждённых находок нет0Внешние команды
v4 27 июн. 2026 г., 16:33 1 подтверждено0 Внешние команды
v3 16 янв. 2026 г., 11:56 Подтверждённых находок нет0Возможности не изменились
v2 16 янв. 2026 г., 11:56 Подтверждённых находок нет0Внешние команды
v1 10 янв. 2026 г., 09:07 Подтверждённых находок нет0Базовая

27 июн. 2026 г., 16:33

The static analyzer findings are false positives caused by Markdown code fences, inline code identifiers, and architecture notes in SKILL.md. No executable script, command invocation, weak cryptographic implementation, prompt injection, data exfiltration, secret access, or destructive behavior was found. The skill is documentation-only and is safe to publish.

1
Просканировано файлов
373
Проанализировано строк
1
Пункты проверки
2
Ложные срабатывания проигнорированы

Подтверждённые проблемы безопасности (1)

Низкий
Reconnaissance Alerts Are Architecture Documentation
Verdict: FALSE_POSITIVE. The system and network reconnaissance alerts map to prose about project state, Supabase data flow, and development guidance. No scanner, network probing command, host enumeration, or environment discovery instruction is present.
The relevant lines are documentation bullets and coding guidance. I found no commands such as nmap, netcat, ipconfig, whoami, or similar reconnaissance tooling.
Статические ложные срабатывания проигнорированы (2)

Эти статические совпадения были отклонены семантической проверкой или совпадали только со схемными токенами, поэтому они показываются для прозрачности, но не влияют на оценку качества.

Низкий
Static Analyzer False Positives in Markdown Reference Text
Verdict: FALSE_POSITIVE. The external command alerts point to Markdown code fences, TypeScript examples, inline function names, and architecture diagrams. These lines document React hooks, utility functions, and project structure; they do not instruct the agent to execute shell commands.
The flagged locations are visibly Markdown fences or inline TypeScript examples. There is no shell syntax, subprocess API, or instruction to run commands.
Низкий
Weak Cryptography Alerts Are Textual Matches Only
Verdict: FALSE_POSITIVE. The weak cryptographic algorithm alerts do not correspond to any cryptographic implementation. The referenced lines describe the skill, sorting behavior, metric names, data interfaces, and callback examples.
The reviewed lines contain no MD5, SHA-1, crypto library usage, random token generation, or authentication logic. The alerts are substring matches in documentation.
Аудитор:: codex

16 янв. 2026 г., 11:56

Pure documentation skill containing only markdown reference material for Portfolio Buddy 2. No executable code, scripts, network calls, filesystem access, or external command execution. All 94 static findings are false positives: backticks are markdown formatting, and 'sharpe'/'sortino' are financial metrics, not cryptographic algorithms.

2
Просканировано файлов
551
Проанализировано строк
1
Пункты проверки
0
Ложные срабатывания проигнорированы
Аудитор:: claude

16 янв. 2026 г., 11:56

Pure documentation skill containing only markdown reference material for Portfolio Buddy 2. No executable code, scripts, network calls, filesystem access, or external command execution. All 94 static findings are false positives: backticks are markdown formatting, and 'sharpe'/'sortino' are financial metrics, not cryptographic algorithms.

2
Просканировано файлов
551
Проанализировано строк
1
Пункты проверки
0
Ложные срабатывания проигнорированы
Аудитор:: claude

10 янв. 2026 г., 09:07

Pure documentation skill containing only markdown reference material for Portfolio Buddy 2. No executable code, scripts, network calls, filesystem access, or external command execution. Safe for distribution.

1
Просканировано файлов
373
Проанализировано строк
0
Пункты проверки
0
Ложные срабатывания проигнорированы
В этом завершенном аудите не зафиксировано подтвержденных проблем безопасности.
Аудитор:: claude