История аудитов
plan-directory - 8 аудиты
Сравнение версий
Изменения возможностей и находок между проверенными версиями, сначала новые.
| Версия | Дата | Результат | Пункты проверки | Изменение к предыдущей |
|---|---|---|---|---|
| v8 Последняя | 5 июл. 2026 г., 13:25 | 1 подтверждено | 0 | Возможности не изменились |
| v7 | 5 июл. 2026 г., 13:25 | 1 подтверждено | 0 | Возможности не изменились |
| v6 | 29 июн. 2026 г., 18:28 | Подтверждённых находок нет | 4 | Возможности не изменились |
| v5 | 17 янв. 2026 г., 03:21 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v4 | 17 янв. 2026 г., 03:21 | Подтверждённых находок нет | 0 | Внешние командыДоступ к файловой системе |
| v3 | 10 янв. 2026 г., 14:16 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v2 | 10 янв. 2026 г., 14:16 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v1 | 10 янв. 2026 г., 14:16 | Подтверждённых находок нет | 0 | Базовая |
5 июл. 2026 г., 13:25
All 81 static findings were reviewed against SKILL.md. The backtick, path traversal, and reconnaissance alerts are false positives from Markdown examples, template paths, and test text. A low severity semantic issue remains because the front matter grants Bash even though the workflow only needs file and glob operations.
Подтверждённые проблемы безопасности (1)
Факторы риска
⚙️ Внешние команды (71)
📁 Доступ к файловой системе (1)
5 июл. 2026 г., 13:25
All 81 static findings were reviewed against SKILL.md. The backtick, path traversal, and reconnaissance alerts are false positives from Markdown examples, template paths, and test text. A low severity semantic issue remains because the front matter grants Bash even though the workflow only needs file and glob operations.
Подтверждённые проблемы безопасности (1)
Факторы риска
⚙️ Внешние команды (71)
📁 Доступ к файловой системе (1)
29 июн. 2026 г., 18:28
Static analysis reported many command, traversal, crypto, and reconnaissance patterns, but review found they are primarily markdown examples, inline filenames, template paths, and authentication examples. The remaining real risk is operational: the skill is allowed to read, write, edit, glob, and use Bash while creating plan directories, so users should review target paths before execution.
Пункты проверки возможностей (4)
Это реальные локальные возможности, которые могут ожидаться для этого навыка, поэтому они требуют проверки, но не считаются подтверждённым вредоносным поведением.
Статические ложные срабатывания проигнорированы (1)
Эти статические совпадения были отклонены семантической проверкой или совпадали только со схемными токенами, поэтому они показываются для прозрачности, но не влияют на оценку качества.
Факторы риска
📁 Доступ к файловой системе (6)
⚙️ Внешние команды (5)
Обнаруженные паттерны
17 янв. 2026 г., 03:21
Pure prompt-based skill containing only markdown documentation and planning templates. No executable code, scripts, network calls, or file system operations beyond standard LLM tool usage. The static analyzer misinterpreted documentation examples as executable code and flagged harmless technical terminology (hash strings, cryptographic word examples, markdown code block syntax).
Факторы риска
⚙️ Внешние команды (75)
📁 Доступ к файловой системе (1)
17 янв. 2026 г., 03:21
Pure prompt-based skill containing only markdown documentation and planning templates. No executable code, scripts, network calls, or file system operations beyond standard LLM tool usage. The static analyzer misinterpreted documentation examples as executable code and flagged harmless technical terminology (hash strings, cryptographic word examples, markdown code block syntax).
Факторы риска
⚙️ Внешние команды (75)
📁 Доступ к файловой системе (1)
10 янв. 2026 г., 14:16
Pure prompt-based skill containing only markdown documentation and planning templates. No executable code, scripts, network calls, or file system operations beyond standard LLM tool usage. Safe for publishing.
10 янв. 2026 г., 14:16
Pure prompt-based skill containing only markdown documentation and planning templates. No executable code, scripts, network calls, or file system operations beyond standard LLM tool usage. Safe for publishing.
10 янв. 2026 г., 14:16
Pure prompt-based skill containing only markdown documentation and planning templates. No executable code, scripts, network calls, or file system operations beyond standard LLM tool usage. Safe for publishing.