История аудитов
bruno-api - 9 аудиты
Сравнение версий
Изменения возможностей и находок между проверенными версиями, сначала новые.
| Версия | Дата | Результат | Пункты проверки | Изменение к предыдущей |
|---|---|---|---|---|
| v9 Последняя | 6 июл. 2026 г., 11:28 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v8 | 6 июл. 2026 г., 11:28 | Подтверждённых находок нет | 0 | Доступ к файловой системе |
| v7 | 29 июн. 2026 г., 18:16 | 1 подтверждено | 0 | Внешние командыДоступ к файловой системе |
| v6 | 21 янв. 2026 г., 18:07 | Подтверждённых находок нет | 0 | Внешние команды |
| v5 | 17 янв. 2026 г., 03:11 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v4 | 17 янв. 2026 г., 03:11 | Подтверждённых находок нет | 0 | Внешние команды |
| v3 | 10 янв. 2026 г., 14:08 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v2 | 10 янв. 2026 г., 14:08 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v1 | 10 янв. 2026 г., 14:08 | Подтверждённых находок нет | 0 | Базовая |
6 июл. 2026 г., 11:28
All static external command findings are false positives caused by Markdown backticks in documentation text. The skill describes reading Bruno files, searching Django code, and optionally writing generated documentation, with no evidence of prompt injection or malicious intent.
Факторы риска
⚙️ Внешние команды (38)
6 июл. 2026 г., 11:28
All static external command findings are false positives caused by Markdown backticks in documentation text. The skill describes reading Bruno files, searching Django code, and optionally writing generated documentation, with no evidence of prompt injection or malicious intent.
Факторы риска
⚙️ Внешние команды (38)
29 июн. 2026 г., 18:16
AI review dismissed the static external-command and weak-cryptography alerts as false positives from Markdown prose and inline literals. The skill has low residual risk because it declares Bash and file editing tools and can write documentation to user-specified paths.
Подтверждённые проблемы безопасности (1)
Статические ложные срабатывания проигнорированы (2)
Эти статические совпадения были отклонены семантической проверкой или совпадали только со схемными токенами, поэтому они показываются для прозрачности, но не влияют на оценку качества.
Факторы риска
⚙️ Внешние команды (1)
📁 Доступ к файловой системе (2)
21 янв. 2026 г., 18:07
This skill is a documentation generator for Bruno API test files. All 56 static findings are false positives: C2 keywords and weak crypto patterns are markdown formatting artifacts, shell backticks are inline code syntax in documentation, and the hardcoded URL is the GitHub source reference. The skill uses only Read, Edit, Glob, Grep, and Bash tools for legitimate documentation generation purposes.
17 янв. 2026 г., 03:11
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Факторы риска
⚙️ Внешние команды (44)
Обнаруженные паттерны
17 янв. 2026 г., 03:11
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Факторы риска
⚙️ Внешние команды (44)
Обнаруженные паттерны
10 янв. 2026 г., 14:08
This is a pure prompt-based skill containing only documentation generation instructions. No executable code, network calls, or file system modifications beyond standard read operations. The skill uses only safe read-only analysis tools (Read, Glob, Grep) with optional Bash for file discovery.
10 янв. 2026 г., 14:08
This is a pure prompt-based skill containing only documentation generation instructions. No executable code, network calls, or file system modifications beyond standard read operations. The skill uses only safe read-only analysis tools (Read, Glob, Grep) with optional Bash for file discovery.
10 янв. 2026 г., 14:08
This is a pure prompt-based skill containing only documentation generation instructions. No executable code, network calls, or file system modifications beyond standard read operations. The skill uses only safe read-only analysis tools (Read, Glob, Grep) with optional Bash for file discovery.