監査履歴
create-pr - 10 監査
バージョン比較
監査済みバージョン間の機能と検出結果の変化(新しい順)。
| バージョン | 日付 | 結果 | レビュー項目 | 前バージョンとの変化 |
|---|---|---|---|---|
| v10 最新 | 9 июл. 2026 г., 11:31 | 確認された検出結果なし | 4 | 機能の変化なし |
| v9 | 9 июл. 2026 г., 11:31 | 確認された検出結果なし | 4 | 機能の変化なし |
| v8 | 5 июл. 2026 г., 07:14 | 確認された検出結果なし | 4 | 機能の変化なし |
| v7 | 5 июл. 2026 г., 07:14 | 確認された検出結果なし | 4 | 機能の変化なし |
| v6 | 29 июн. 2026 г., 03:32 | 確認された検出結果なし | 2 | 機能の変化なし |
| v5 | 16 янв. 2026 г., 22:50 | 確認された検出結果なし | 0 | 機能の変化なし |
| v4 | 16 янв. 2026 г., 22:50 | 確認された検出結果なし | 0 | 外部コマンドネットワークアクセス |
| v3 | 10 янв. 2026 г., 12:45 | 確認された検出結果なし | 0 | 機能の変化なし |
| v2 | 10 янв. 2026 г., 12:45 | 確認された検出結果なし | 0 | 機能の変化なし |
| v1 | 10 янв. 2026 г., 12:45 | 確認された検出結果なし | 0 | 基準 |
9 июл. 2026 г., 11:31
Most static findings are false positives from Markdown fences, inline backticks, and readable Japanese documentation. The confirmed risks are the state-changing git push and gh pr create workflow, plus avoidable shell construction for the generated PR body. No prompt injection, malicious network endpoint, or obfuscated payload evidence was found.
機能レビュー項目 (4)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (29)
🌐 ネットワークアクセス (1)
9 июл. 2026 г., 11:31
Most static findings are false positives from Markdown fences, inline backticks, and readable Japanese documentation. The confirmed risks are the state-changing git push and gh pr create workflow, plus avoidable shell construction for the generated PR body. No prompt injection, malicious network endpoint, or obfuscated payload evidence was found.
機能レビュー項目 (4)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (29)
🌐 ネットワークアクセス (1)
5 июл. 2026 г., 07:14
No prompt injection or obfuscated payload was found in SKILL.md; the high-entropy alert is a false positive from readable Markdown and Japanese text. Most command detections are Markdown fences, inline labels, or fixed read-only git checks. The material risk is intended remote mutation through git push, gh pr create, and shell command substitution for the PR body.
機能レビュー項目 (4)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (29)
🌐 ネットワークアクセス (1)
5 июл. 2026 г., 07:14
No prompt injection or obfuscated payload was found in SKILL.md; the high-entropy alert is a false positive from readable Markdown and Japanese text. Most command detections are Markdown fences, inline labels, or fixed read-only git checks. The material risk is intended remote mutation through git push, gh pr create, and shell command substitution for the PR body.
機能レビュー項目 (4)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (29)
🌐 ネットワークアクセス (1)
29 июн. 2026 г., 03:32
Static command findings are mostly Markdown code fences and inline examples, so the Ruby backtick and high entropy alerts are false positives. The skill does instruct agents to run git and gh commands that push branches and create pull requests, which is legitimate but state-changing automation. No prompt injection, credential exfiltration, malware behavior, or hidden network destination was found.
機能レビュー項目 (2)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
静的解析の誤検知を無視 (3)
これらの静的マッチはセマンティックレビューで却下されたか、スキーマのみのトークンに一致したため、透明性のために表示されていますが、品質スコアには影響しません。
リスク要因
⚙️ 外部コマンド (8)
🌐 ネットワークアクセス (1)
検出されたパターン
16 янв. 2026 г., 22:50
This is a pure SKILL.md documentation file containing only markdown instructions for AI agents. Static findings are false positives caused by the scanner treating markdown code blocks as executable code, Japanese text as 'obfuscated content', and documentation URLs as network calls. All described operations (git diff, gh CLI) are legitimate development tooling.
リスク要因
⚙️ 外部コマンド (1)
🌐 ネットワークアクセス (1)
16 янв. 2026 г., 22:50
This is a pure SKILL.md documentation file containing only markdown instructions for AI agents. Static findings are false positives caused by the scanner treating markdown code blocks as executable code, Japanese text as 'obfuscated content', and documentation URLs as network calls. All described operations (git diff, gh CLI) are legitimate development tooling.
リスク要因
⚙️ 外部コマンド (1)
🌐 ネットワークアクセス (1)
10 янв. 2026 г., 12:45
This is a pure skill definition file (SKILL.md) containing only markdown documentation and AI instructions. No executable code is present. The described capabilities (git operations, gh CLI) match the stated purpose of GitHub PR automation. No network calls, file access beyond repository scope, or code execution patterns detected.
10 янв. 2026 г., 12:45
This is a pure skill definition file (SKILL.md) containing only markdown documentation and AI instructions. No executable code is present. The described capabilities (git operations, gh CLI) match the stated purpose of GitHub PR automation. No network calls, file access beyond repository scope, or code execution patterns detected.
10 янв. 2026 г., 12:45
This is a pure skill definition file (SKILL.md) containing only markdown documentation and AI instructions. No executable code is present. The described capabilities (git operations, gh CLI) match the stated purpose of GitHub PR automation. No network calls, file access beyond repository scope, or code execution patterns detected.