История аудитов
Writing Hookify Rules - 9 аудиты
Сравнение версий
Изменения возможностей и находок между проверенными версиями, сначала новые.
| Версия | Дата | Результат | Пункты проверки | Изменение к предыдущей |
|---|---|---|---|---|
| v9 Последняя | 18 июл. 2026 г., 14:17 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v8 | 7 июл. 2026 г., 22:36 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v7 | 6 июл. 2026 г., 03:36 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v6 | 6 июл. 2026 г., 03:36 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v5 | 28 июн. 2026 г., 09:39 | Подтверждённых находок нет | 0 | Доступ к сети |
| v4 | 16 янв. 2026 г., 15:05 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v3 | 16 янв. 2026 г., 15:05 | Подтверждённых находок нет | 0 | Доступ к сети |
| v2 | 11 янв. 2026 г., 07:24 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v1 | 11 янв. 2026 г., 07:24 | Подтверждённых находок нет | 0 | Базовая |
18 июл. 2026 г., 14:17
All 116 static findings are false positives caused by Markdown backticks, fenced examples, and literal regex patterns documenting defensive rules. SKILL.md does not execute code, access secrets, or instruct users to run destructive commands; it teaches rules that warn or block those patterns.
Факторы риска
⚡ Содержит скрипты (2)
⚙️ Внешние команды (50)
🔑 Переменные окружения (2)
7 июл. 2026 г., 22:36
The flagged items in SKILL.md are documentation examples, Markdown code fences, or inline regex patterns for Hookify rule authoring. I found no executable scripts, secret reads, prompt injection, or data exfiltration behavior in the skill file.
Факторы риска
⚡ Содержит скрипты (2)
⚙️ Внешние команды (105)
🔑 Переменные окружения (2)
6 июл. 2026 г., 03:36
Static analysis reported many risky strings, but review found they are documentation examples inside SKILL.md, not executable code. The skill explains how to write rules that warn about dangerous commands and sensitive files; it does not run commands, read secrets, or include prompt injection attempts.
Статические ложные срабатывания проигнорированы (3)
Эти статические совпадения были отклонены семантической проверкой или совпадали только со схемными токенами, поэтому они показываются для прозрачности, но не влияют на оценку качества.
Факторы риска
⚡ Содержит скрипты (2)
⚙️ Внешние команды (105)
🔑 Переменные окружения (2)
6 июл. 2026 г., 03:36
Static analysis reported many risky strings, but review found they are documentation examples inside SKILL.md, not executable code. The skill explains how to write rules that warn about dangerous commands and sensitive files; it does not run commands, read secrets, or include prompt injection attempts.
Статические ложные срабатывания проигнорированы (3)
Эти статические совпадения были отклонены семантической проверкой или совпадали только со схемными токенами, поэтому они показываются для прозрачности, но не влияют на оценку качества.
Факторы риска
⚡ Содержит скрипты (2)
⚙️ Внешние команды (105)
🔑 Переменные окружения (2)
28 июн. 2026 г., 09:39
Static analysis flagged many dangerous command, code execution, and secret-related strings in SKILL.md. Human review found these are markdown examples for writing defensive Hookify rules, not executable code, command execution, or credential access. No prompt injection, data exfiltration, network behavior, or malicious intent was found.
Статические ложные срабатывания проигнорированы (3)
Эти статические совпадения были отклонены семантической проверкой или совпадали только со схемными токенами, поэтому они показываются для прозрачности, но не влияют на оценку качества.
Факторы риска
⚡ Содержит скрипты (1)
⚙️ Внешние команды (3)
🔑 Переменные окружения (4)
16 янв. 2026 г., 15:05
All static findings are FALSE POSITIVES. This skill is documentation-only that teaches users how to write Hookify rules to DETECT dangerous patterns like eval(), rm -rf, chmod 777, and secret exposure. The 'dangerous' strings appear only as regex patterns in examples, never as executable code. The skill's purpose is defensive security education for Claude workflows.
Факторы риска
⚡ Содержит скрипты (1)
⚙️ Внешние команды (1)
🔑 Переменные окружения (1)
🌐 Доступ к сети (1)
16 янв. 2026 г., 15:05
All static findings are FALSE POSITIVES. This skill is documentation-only that teaches users how to write Hookify rules to DETECT dangerous patterns like eval(), rm -rf, chmod 777, and secret exposure. The 'dangerous' strings appear only as regex patterns in examples, never as executable code. The skill's purpose is defensive security education for Claude workflows.
Факторы риска
⚡ Содержит скрипты (1)
⚙️ Внешние команды (1)
🔑 Переменные окружения (1)
🌐 Доступ к сети (1)
11 янв. 2026 г., 07:24
All 156 static findings are FALSE POSITIVES. This skill is documentation-only, teaching users how to write Hookify rules that DETECT dangerous patterns like eval(), rm -rf, and chmod 777. The 'dangerous' strings appear only as regex patterns to match, never as executed code. The skill's purpose is defensive security education.
Факторы риска
⚡ Содержит скрипты (1)
⚙️ Внешние команды (1)
🔑 Переменные окружения (1)
11 янв. 2026 г., 07:24
All 156 static findings are FALSE POSITIVES. This skill is documentation-only, teaching users how to write Hookify rules that DETECT dangerous patterns like eval(), rm -rf, and chmod 777. The 'dangerous' strings appear only as regex patterns to match, never as executed code. The skill's purpose is defensive security education.