Навыки bruno-api История аудитов
📦

История аудитов

bruno-api - 9 аудиты

Сравнение версий

Изменения возможностей и находок между проверенными версиями, сначала новые.

ВерсияДатаРезультатПункты проверкиИзменение к предыдущей
v9 Последняя6 июл. 2026 г., 11:28 Подтверждённых находок нет0Возможности не изменились
v8 6 июл. 2026 г., 11:28 Подтверждённых находок нет0 Доступ к файловой системе
v7 29 июн. 2026 г., 18:16 1 подтверждено0Внешние командыДоступ к файловой системе
v6 21 янв. 2026 г., 18:07 Подтверждённых находок нет0 Внешние команды
v5 17 янв. 2026 г., 03:11 Подтверждённых находок нет0Возможности не изменились
v4 17 янв. 2026 г., 03:11 Подтверждённых находок нет0Внешние команды
v3 10 янв. 2026 г., 14:08 Подтверждённых находок нет0Возможности не изменились
v2 10 янв. 2026 г., 14:08 Подтверждённых находок нет0Возможности не изменились
v1 10 янв. 2026 г., 14:08 Подтверждённых находок нет0Базовая
Версия аудита 9 Последняя

6 июл. 2026 г., 11:28

All static external command findings are false positives caused by Markdown backticks in documentation text. The skill describes reading Bruno files, searching Django code, and optionally writing generated documentation, with no evidence of prompt injection or malicious intent.

1
Просканировано файлов
171
Проанализировано строк
1
Пункты проверки
0
Ложные срабатывания проигнорированы
Аудитор:: codex

6 июл. 2026 г., 11:28

All static external command findings are false positives caused by Markdown backticks in documentation text. The skill describes reading Bruno files, searching Django code, and optionally writing generated documentation, with no evidence of prompt injection or malicious intent.

1
Просканировано файлов
171
Проанализировано строк
1
Пункты проверки
0
Ложные срабатывания проигнорированы
Аудитор:: codex

29 июн. 2026 г., 18:16

AI review dismissed the static external-command and weak-cryptography alerts as false positives from Markdown prose and inline literals. The skill has low residual risk because it declares Bash and file editing tools and can write documentation to user-specified paths.

1
Просканировано файлов
171
Проанализировано строк
3
Пункты проверки
2
Ложные срабатывания проигнорированы

Подтверждённые проблемы безопасности (1)

Низкий
Broad Local Tool Permissions Require Normal User Caution
The skill declares Bash and file editing tools and can write generated documentation to a user-provided output path. This is legitimate for documentation generation but should remain limited to trusted repositories.
The tool declarations and output-writing workflow are explicit. I found no malicious command, but the capability can modify local files when the user asks for output writing.
Статические ложные срабатывания проигнорированы (2)

Эти статические совпадения были отклонены семантической проверкой или совпадали только со схемными токенами, поэтому они показываются для прозрачности, но не влияют на оценку качества.

Низкий
Static Backtick Command Findings Are Markdown Literals
The analyzer flagged Markdown inline code and command-like documentation as Ruby shell execution. These lines describe file names, headings, CLI flags, or output sections and are not executable code.
The file is Markdown skill instructions, and the flagged backticks mark literal examples or labels. I found no Ruby source, script file, or shell expansion syntax at these locations.
Низкий
Weak Cryptography Findings Are Prose Substring Matches
The high-severity weak cryptography alerts are false positives. The flagged lines contain description text, a section title, and compatibility prose, not cryptographic functions or algorithms.
Line review shows ordinary prose and frontmatter, with no hash, cipher, password, or transport-security implementation. The matches appear to come from substrings inside words.

Факторы риска

⚙️ Внешние команды (1)
📁 Доступ к файловой системе (2)
Аудитор:: codex

21 янв. 2026 г., 18:07

This skill is a documentation generator for Bruno API test files. All 56 static findings are false positives: C2 keywords and weak crypto patterns are markdown formatting artifacts, shell backticks are inline code syntax in documentation, and the hardcoded URL is the GitHub source reference. The skill uses only Read, Edit, Glob, Grep, and Bash tools for legitimate documentation generation purposes.

2
Просканировано файлов
804
Проанализировано строк
0
Пункты проверки
0
Ложные срабатывания проигнорированы
В этом завершенном аудите не зафиксировано подтвержденных проблем безопасности.
Аудитор:: claude

17 янв. 2026 г., 03:11

AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.

2
Просканировано файлов
364
Проанализировано строк
1
Пункты проверки
0
Ложные срабатывания проигнорированы

Обнаруженные паттерны

Weak cryptographic algorithmRuby/shell backtick execution
Аудитор:: claude

17 янв. 2026 г., 03:11

AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.

2
Просканировано файлов
364
Проанализировано строк
1
Пункты проверки
0
Ложные срабатывания проигнорированы

Обнаруженные паттерны

Weak cryptographic algorithmRuby/shell backtick execution
Аудитор:: claude

10 янв. 2026 г., 14:08

This is a pure prompt-based skill containing only documentation generation instructions. No executable code, network calls, or file system modifications beyond standard read operations. The skill uses only safe read-only analysis tools (Read, Glob, Grep) with optional Bash for file discovery.

1
Просканировано файлов
171
Проанализировано строк
0
Пункты проверки
0
Ложные срабатывания проигнорированы
В этом завершенном аудите не зафиксировано подтвержденных проблем безопасности.
Аудитор:: claude

10 янв. 2026 г., 14:08

This is a pure prompt-based skill containing only documentation generation instructions. No executable code, network calls, or file system modifications beyond standard read operations. The skill uses only safe read-only analysis tools (Read, Glob, Grep) with optional Bash for file discovery.

1
Просканировано файлов
171
Проанализировано строк
0
Пункты проверки
0
Ложные срабатывания проигнорированы
В этом завершенном аудите не зафиксировано подтвержденных проблем безопасности.
Аудитор:: claude

10 янв. 2026 г., 14:08

This is a pure prompt-based skill containing only documentation generation instructions. No executable code, network calls, or file system modifications beyond standard read operations. The skill uses only safe read-only analysis tools (Read, Glob, Grep) with optional Bash for file discovery.

1
Просканировано файлов
171
Проанализировано строк
0
Пункты проверки
0
Ложные срабатывания проигнорированы
В этом завершенном аудите не зафиксировано подтвержденных проблем безопасности.
Аудитор:: claude