История аудитов
skill-creator - 6 аудиты
Сравнение версий
Изменения возможностей и находок между проверенными версиями, сначала новые.
| Версия | Дата | Результат | Пункты проверки | Изменение к предыдущей |
|---|---|---|---|---|
| v6 Последняя | 4 июл. 2026 г., 17:39 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v5 | 4 июл. 2026 г., 17:39 | Подтверждённых находок нет | 0 | Внешние команды Содержит скрипты |
| v4 | 27 июн. 2026 г., 17:20 | 2 подтверждено | 0 | Возможности не изменились |
| v3 | 16 янв. 2026 г., 13:46 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v2 | 16 янв. 2026 г., 13:46 | Подтверждённых находок нет | 0 | Содержит скриптыДоступ к файловой системе |
| v1 | 10 янв. 2026 г., 09:41 | Подтверждённых находок нет | 0 | Базовая |
4 июл. 2026 г., 17:39
All 50 static findings were adjudicated as false positives after reviewing the cited files. The alerts come from markdown backticks, archive packaging used for .skill creation, dictionary key validation, and normal validator exits. No prompt injection, credential access, network exfiltration, or malicious intent was found.
Факторы риска
⚙️ Внешние команды (40)
📁 Доступ к файловой системе (2)
4 июл. 2026 г., 17:39
All 50 static findings were adjudicated as false positives after reviewing the cited files. The alerts come from markdown backticks, archive packaging used for .skill creation, dictionary key validation, and normal validator exits. No prompt injection, credential access, network exfiltration, or malicious intent was found.
Факторы риска
⚙️ Внешние команды (40)
📁 Доступ к файловой системе (2)
27 июн. 2026 г., 17:20
Static analysis reported many high and critical patterns, but review found those are mainly false positives from Markdown fences, Apache license URLs, and template text. No evidence found of prompt injection, network exfiltration, credential files, weak cryptography, system reconnaissance, or command execution. The remaining publishable risk is filesystem behavior: scripts can create files and recursively package folder contents.
Подтверждённые проблемы безопасности (2)
Статические ложные срабатывания проигнорированы (2)
Эти статические совпадения были отклонены семантической проверкой или совпадали только со схемными токенами, поэтому они показываются для прозрачности, но не влияют на оценку качества.
Факторы риска
⚡ Содержит скрипты (3)
📁 Доступ к файловой системе (4)
Обнаруженные паттерны
16 янв. 2026 г., 13:46
This is a documentation and utility skill for creating other skills. It contains Python scripts for skill initialization, validation, and packaging. All scripts operate locally on the filesystem, create directories and files at user-specified paths, and make no network calls or external command executions. The extensive static findings are false positives caused by markdown code block markers being misidentified as shell backticks, and text patterns in documentation being misidentified as cryptographic terms.
Факторы риска
⚡ Содержит скрипты (3)
📁 Доступ к файловой системе (2)
16 янв. 2026 г., 13:46
This is a documentation and utility skill for creating other skills. It contains Python scripts for skill initialization, validation, and packaging. All scripts operate locally on the filesystem, create directories and files at user-specified paths, and make no network calls or external command executions. The extensive static findings are false positives caused by markdown code block markers being misidentified as shell backticks, and text patterns in documentation being misidentified as cryptographic terms.
Факторы риска
⚡ Содержит скрипты (3)
📁 Доступ к файловой системе (2)
10 янв. 2026 г., 09:41
This is a documentation and utility skill for creating other skills. It contains Python scripts for skill initialization, validation, and packaging. All scripts operate locally on filesystem, create directories and files at user-specified paths, and make no network calls or external command executions. No sensitive data access detected.