Навыки techdoc-search-and-orchestrate История аудитов
📦

История аудитов

techdoc-search-and-orchestrate - 7 аудиты

Сравнение версий

Изменения возможностей и находок между проверенными версиями, сначала новые.

ВерсияДатаРезультатПункты проверкиИзменение к предыдущей
v7 Последняя4 июл. 2026 г., 17:17 Подтверждённых находок нет0Возможности не изменились
v6 4 июл. 2026 г., 17:17 Подтверждённых находок нет0Внешние команды
v5 27 июн. 2026 г., 17:02 Подтверждённых находок нет0Возможности не изменились
v4 21 янв. 2026 г., 16:00 Подтверждённых находок нет0 Внешние команды
v3 16 янв. 2026 г., 12:33 Подтверждённых находок нет0Возможности не изменились
v2 16 янв. 2026 г., 12:33 Подтверждённых находок нет0Внешние команды
v1 10 янв. 2026 г., 09:20 Подтверждённых находок нет0Базовая
Версия аудита 7 Последняя

4 июл. 2026 г., 17:17

Manual review found the external command alerts are false positives from Markdown inline code and fenced examples. The high-entropy alert is also a false positive because SKILL.md is readable Markdown, not obfuscated content. No evidence found for command execution, data exfiltration, or prompt injection intent.

1
Просканировано файлов
158
Проанализировано строк
1
Пункты проверки
0
Ложные срабатывания проигнорированы
Аудитор:: codex

4 июл. 2026 г., 17:17

Manual review found the external command alerts are false positives from Markdown inline code and fenced examples. The high-entropy alert is also a false positive because SKILL.md is readable Markdown, not obfuscated content. No evidence found for command execution, data exfiltration, or prompt injection intent.

1
Просканировано файлов
158
Проанализировано строк
1
Пункты проверки
0
Ложные срабатывания проигнорированы
Аудитор:: codex

27 июн. 2026 г., 17:02

The static analyzer flagged backticks, DES-like substrings, and high entropy, but the reviewed file is a Markdown orchestration guide. No shell execution, weak cryptography, binary payload, data exfiltration, or prompt injection attempt was found. The residual risk is low because it depends on a named subagent and Context7 workflow.

1
Просканировано файлов
158
Проанализировано строк
0
Пункты проверки
3
Ложные срабатывания проигнорированы
Статические ложные срабатывания проигнорированы (3)

Эти статические совпадения были отклонены семантической проверкой или совпадали только со схемными токенами, поэтому они показываются для прозрачности, но не влияют на оценку качества.

Низкий
False Positive: Markdown Backticks Misread as Shell Execution
Verdict: FALSE_POSITIVE. The flagged backticks mark inline tool names and fenced examples for Task tool parameters. They do not execute commands or pass user input to a shell.
The reviewed content is Markdown prose and examples only. I found no shell command syntax, script file, interpreter call, or command execution API.
Низкий
False Positive: Weak Crypto Pattern from Description Fields
Verdict: FALSE_POSITIVE. The weak cryptography hits align with frontmatter and Task parameter names such as description. No encryption algorithm or cryptographic operation is present.
The matched locations are labels and natural-language descriptions. I found no DES, MD5, cipher selection, hashing code, or credential handling.
Низкий
False Positive: High Entropy from Multilingual Markdown
Verdict: FALSE_POSITIVE. The file is Chinese Markdown text with examples. No encoded blob, binary content, packed script, or hidden payload was found.
The entire file is readable Markdown with frontmatter, headings, and examples. The high entropy score is consistent with multilingual text, not obfuscation.
В этом завершенном аудите не зафиксировано подтвержденных проблем безопасности.
Аудитор:: codex

21 янв. 2026 г., 16:00

All static findings are false positives. The skill is a pure orchestration layer that delegates to another agent using Task tool. No network calls, file operations, or command execution occur. Static scanner misidentified markdown code fences as shell backticks and UTF-8 Chinese text as encrypted content.

2
Просканировано файлов
592
Проанализировано строк
0
Пункты проверки
0
Ложные срабатывания проигнорированы
В этом завершенном аудите не зафиксировано подтвержденных проблем безопасности.
Аудитор:: claude

16 янв. 2026 г., 12:33

AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.

2
Просканировано файлов
336
Проанализировано строк
1
Пункты проверки
0
Ложные срабатывания проигнорированы

Обнаруженные паттерны

Weak cryptographic algorithmRuby/shell backtick execution[HEURISTIC] High file entropy (6.64 bits) - possible binary/encrypted content
Аудитор:: claude

16 янв. 2026 г., 12:33

AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.

2
Просканировано файлов
336
Проанализировано строк
1
Пункты проверки
0
Ложные срабатывания проигнорированы

Обнаруженные паттерны

Weak cryptographic algorithmRuby/shell backtick execution[HEURISTIC] High file entropy (6.64 bits) - possible binary/encrypted content
Аудитор:: claude

10 янв. 2026 г., 09:20

This is a prompt-only skill containing only documentation and task orchestration guidelines. No executable code, scripts, network operations, or file system modifications detected. The skill provides instructions for delegating technical documentation queries to a Context7 researcher agent using standard Task tool functionality.

1
Просканировано файлов
158
Проанализировано строк
0
Пункты проверки
0
Ложные срабатывания проигнорированы
В этом завершенном аудите не зафиксировано подтвержденных проблем безопасности.
Аудитор:: claude