Audit-Verlauf
code-reviewer - 8 Audits
Versionsvergleich
Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.
| Version | Datum | Ergebnis | Prüfelemente | Änderung ggü. vorheriger |
|---|---|---|---|---|
| v8 Neueste | 9 июл. 2026 г., 11:07 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v7 | 9 июл. 2026 г., 11:07 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v6 | 6 июл. 2026 г., 00:37 | Keine bestätigten Befunde | 3 | Keine Änderung der Fähigkeiten |
| v5 | 6 июл. 2026 г., 00:37 | Keine bestätigten Befunde | 3 | Keine Änderung der Fähigkeiten |
| v4 | 28 июн. 2026 г., 08:41 | 1 bestätigt | 1 | Keine Änderung der Fähigkeiten |
| v3 | 16 янв. 2026 г., 15:43 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v2 | 16 янв. 2026 г., 15:43 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v1 | 15 янв. 2026 г., 11:35 | Keine bestätigten Befunde | 0 | Ausgangsbasis |
9 июл. 2026 г., 11:07
I found no evidence of malicious intent, prompt injection, credential exfiltration, or hidden system reconnaissance. The static findings are documentation headings, Markdown command examples, inline reference paths, and optional user-directed JSON output writes.
Risikofaktoren
📁 Dateisystemzugriff (3)
⚙️ Externe Befehle (24)
9 июл. 2026 г., 11:07
I found no evidence of malicious intent, prompt injection, credential exfiltration, or hidden system reconnaissance. The static findings are documentation headings, Markdown command examples, inline reference paths, and optional user-directed JSON output writes.
Risikofaktoren
📁 Dateisystemzugriff (3)
⚙️ Externe Befehle (24)
6 июл. 2026 г., 00:37
The only confirmed issues are three Python helper scripts that can write JSON reports to any user supplied output path. The Markdown code fences, reference links, anti-pattern headings, and .env template copy are false positives; no prompt injection, credential exfiltration, or network behavior was found.
Elemente der Fähigkeitsprüfung (3)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.
Risikofaktoren
📁 Dateisystemzugriff (3)
⚙️ Externe Befehle (24)
6 июл. 2026 г., 00:37
The only confirmed issues are three Python helper scripts that can write JSON reports to any user supplied output path. The Markdown code fences, reference links, anti-pattern headings, and .env template copy are false positives; no prompt injection, credential exfiltration, or network behavior was found.
Elemente der Fähigkeitsprüfung (3)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.
Risikofaktoren
📁 Dateisystemzugriff (3)
⚙️ Externe Befehle (24)
28 июн. 2026 г., 08:41
Static analysis reported many high-risk patterns, but review found the weak-crypto, reconnaissance, environment-file, and command-execution hits are documentation examples or placeholder text. The only executable behavior of note is optional JSON report writing to a user-supplied output path in the helper scripts, so the skill is low risk and safe to publish.
Bestätigte Sicherheitsbedenken (1)
Elemente der Fähigkeitsprüfung (1)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.
Statische falsch positive Treffer ignoriert (2)
Diese statischen Treffer wurden durch semantische Prüfung verworfen oder entsprachen reinen Schema-Tokens; daher werden sie aus Transparenzgründen angezeigt, beeinflussen jedoch nicht die Qualitätsbewertung.
Risikofaktoren
⚙️ Externe Befehle (13)
📁 Dateisystemzugriff (3)
Erkannte Muster
16 янв. 2026 г., 15:43
All 67 static findings are FALSE POSITIVES. The analyzer misidentified TypeScript template literals in markdown documentation as shell backtick execution, common text headers as weak cryptographic algorithms, and standard markdown sections as system reconnaissance. The actual Python scripts contain only safe file operations with user-specified output paths. No malicious patterns confirmed.
Risikofaktoren
16 янв. 2026 г., 15:43
All 67 static findings are FALSE POSITIVES. The analyzer misidentified TypeScript template literals in markdown documentation as shell backtick execution, common text headers as weak cryptographic algorithms, and standard markdown sections as system reconnaissance. The actual Python scripts contain only safe file operations with user-specified output paths. No malicious patterns confirmed.
Risikofaktoren
15 янв. 2026 г., 11:35
All 57 static findings are FALSE POSITIVEs. The analyzer incorrectly flagged TypeScript template literals in markdown documentation as 'Ruby/shell backtick execution', common text as 'weak cryptographic algorithms', and standard markdown section headers as 'system reconnaissance'. The actual Python scripts contain only safe file operations with hardcoded output paths. No malicious patterns confirmed after evaluation.