История аудитов
managing-workflow - 6 аудиты
Версия аудита 6
Последняя Средний рискJun 28, 2026, 05:15 PM
The static report overstates risk because many high alerts are false positives from Markdown examples, relative imports, and template placeholders. The real risk is moderate: the skill intentionally runs local Node scripts and those scripts can read, write, or move files based on command arguments without strict path validation.
Проблемы среднего риска (2)
Проблемы низкого риска (2)
Факторы риска
⚡ Содержит скрипты (5)
⚙️ Внешние команды (5)
📁 Доступ к файловой системе (8)
🔑 Переменные окружения (1)
Обнаруженные паттерны
Версия аудита 5
БезопасноJan 16, 2026, 07:21 PM
This is a legitimate workflow management skill for specification-driven development. All code operates locally within the project .spec directory. No network access, no credential handling, and no external command execution beyond controlled Node.js script invocations. Behavior matches stated purpose.
Факторы риска
⚡ Содержит скрипты (5)
📁 Доступ к файловой системе (3)
🔑 Переменные окружения (1)
Версия аудита 4
БезопасноJan 16, 2026, 07:21 PM
This is a legitimate workflow management skill for specification-driven development. All code operates locally within the project .spec directory. No network access, no credential handling, and no external command execution beyond controlled Node.js script invocations. Behavior matches stated purpose.
Факторы риска
⚡ Содержит скрипты (5)
📁 Доступ к файловой системе (3)
🔑 Переменные окружения (1)
Версия аудита 3
БезопасноJan 10, 2026, 11:39 AM
This is a legitimate workflow management skill for specification-driven development. All code operates locally within the project .spec directory. No network access, no credential handling, and no external command execution beyond controlled Node.js script invocations. Behavior matches stated purpose.
Факторы риска
⚡ Содержит скрипты (5)
📁 Доступ к файловой системе (3)
🔑 Переменные окружения (1)
Версия аудита 2
БезопасноJan 10, 2026, 11:39 AM
This is a legitimate workflow management skill for specification-driven development. All code operates locally within the project .spec directory. No network access, no credential handling, and no external command execution beyond controlled Node.js script invocations. Behavior matches stated purpose.
Факторы риска
⚡ Содержит скрипты (5)
📁 Доступ к файловой системе (3)
🔑 Переменные окружения (1)
Версия аудита 1
БезопасноJan 10, 2026, 11:39 AM
This is a legitimate workflow management skill for specification-driven development. All code operates locally within the project .spec directory. No network access, no credential handling, and no external command execution beyond controlled Node.js script invocations. Behavior matches stated purpose.