История аудитов
techdoc-search-and-orchestrate - 7 аудиты
Сравнение версий
Изменения возможностей и находок между проверенными версиями, сначала новые.
| Версия | Дата | Результат | Пункты проверки | Изменение к предыдущей |
|---|---|---|---|---|
| v7 Последняя | 4 июл. 2026 г., 17:17 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v6 | 4 июл. 2026 г., 17:17 | Подтверждённых находок нет | 0 | Внешние команды |
| v5 | 27 июн. 2026 г., 17:02 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v4 | 21 янв. 2026 г., 16:00 | Подтверждённых находок нет | 0 | Внешние команды |
| v3 | 16 янв. 2026 г., 12:33 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v2 | 16 янв. 2026 г., 12:33 | Подтверждённых находок нет | 0 | Внешние команды |
| v1 | 10 янв. 2026 г., 09:20 | Подтверждённых находок нет | 0 | Базовая |
4 июл. 2026 г., 17:17
Manual review found the external command alerts are false positives from Markdown inline code and fenced examples. The high-entropy alert is also a false positive because SKILL.md is readable Markdown, not obfuscated content. No evidence found for command execution, data exfiltration, or prompt injection intent.
Факторы риска
⚙️ Внешние команды (19)
4 июл. 2026 г., 17:17
Manual review found the external command alerts are false positives from Markdown inline code and fenced examples. The high-entropy alert is also a false positive because SKILL.md is readable Markdown, not obfuscated content. No evidence found for command execution, data exfiltration, or prompt injection intent.
Факторы риска
⚙️ Внешние команды (19)
27 июн. 2026 г., 17:02
The static analyzer flagged backticks, DES-like substrings, and high entropy, but the reviewed file is a Markdown orchestration guide. No shell execution, weak cryptography, binary payload, data exfiltration, or prompt injection attempt was found. The residual risk is low because it depends on a named subagent and Context7 workflow.
Статические ложные срабатывания проигнорированы (3)
Эти статические совпадения были отклонены семантической проверкой или совпадали только со схемными токенами, поэтому они показываются для прозрачности, но не влияют на оценку качества.
21 янв. 2026 г., 16:00
All static findings are false positives. The skill is a pure orchestration layer that delegates to another agent using Task tool. No network calls, file operations, or command execution occur. Static scanner misidentified markdown code fences as shell backticks and UTF-8 Chinese text as encrypted content.
16 янв. 2026 г., 12:33
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Факторы риска
⚙️ Внешние команды (19)
Обнаруженные паттерны
16 янв. 2026 г., 12:33
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Факторы риска
⚙️ Внешние команды (19)
Обнаруженные паттерны
10 янв. 2026 г., 09:20
This is a prompt-only skill containing only documentation and task orchestration guidelines. No executable code, scripts, network operations, or file system modifications detected. The skill provides instructions for delegating technical documentation queries to a Context7 researcher agent using standard Task tool functionality.