История аудитов
pr-description-writer - 8 аудиты
Сравнение версий
Изменения возможностей и находок между проверенными версиями, сначала новые.
| Версия | Дата | Результат | Пункты проверки | Изменение к предыдущей |
|---|---|---|---|---|
| v8 Последняя | 5 июл. 2026 г., 13:29 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v7 | 5 июл. 2026 г., 13:29 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v6 | 29 июн. 2026 г., 18:31 | Подтверждённых находок нет | 3 | Возможности не изменились |
| v5 | 17 янв. 2026 г., 03:25 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v4 | 17 янв. 2026 г., 03:25 | Подтверждённых находок нет | 0 | Внешние командыДоступ к файловой системе |
| v3 | 10 янв. 2026 г., 14:17 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v2 | 10 янв. 2026 г., 14:17 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v1 | 10 янв. 2026 г., 14:17 | Подтверждённых находок нет | 0 | Базовая |
5 июл. 2026 г., 13:29
Static alerts in SKILL.md are Markdown formatting and documented Git or GitHub CLI examples for collecting PR context and optionally updating PR text. I found no prompt injection, obfuscation, secret exfiltration, or unauthorized command-execution intent. Users should still review generated PR content before publishing it.
Факторы риска
⚙️ Внешние команды (93)
📁 Доступ к файловой системе (9)
5 июл. 2026 г., 13:29
Static alerts in SKILL.md are Markdown formatting and documented Git or GitHub CLI examples for collecting PR context and optionally updating PR text. I found no prompt injection, obfuscation, secret exfiltration, or unauthorized command-execution intent. Users should still review generated PR content before publishing it.
Факторы риска
⚙️ Внешние команды (93)
📁 Доступ к файловой системе (9)
29 июн. 2026 г., 18:31
Static analysis reported many command-execution and weak-cryptography patterns, but review shows the file is a Markdown skill with Git and GitHub CLI examples. The external command use is legitimate for PR description generation, but it can read local diffs and update or create GitHub PRs, so publication should include a permission warning. No evidence found of prompt injection, obfuscated payloads, malicious network endpoints, or credential exfiltration.
Пункты проверки возможностей (3)
Это реальные локальные возможности, которые могут ожидаться для этого навыка, поэтому они требуют проверки, но не считаются подтверждённым вредоносным поведением.
Статические ложные срабатывания проигнорированы (1)
Эти статические совпадения были отклонены семантической проверкой или совпадали только со схемными токенами, поэтому они показываются для прозрачности, но не влияют на оценку качества.
Факторы риска
⚙️ Внешние команды (5)
📁 Доступ к файловой системе (5)
Обнаруженные паттерны
17 янв. 2026 г., 03:25
Pure documentation skill containing only prompt templates and guidelines for writing PR descriptions. All static findings are false positives: markdown code formatting was misidentified as shell execution, JSON metadata fields were misidentified as cryptographic code, and standard git commands were misidentified as reconnaissance. No executable code, no malicious patterns, no data exfiltration.
Факторы риска
⚙️ Внешние команды (98)
📁 Доступ к файловой системе (9)
17 янв. 2026 г., 03:25
Pure documentation skill containing only prompt templates and guidelines for writing PR descriptions. All static findings are false positives: markdown code formatting was misidentified as shell execution, JSON metadata fields were misidentified as cryptographic code, and standard git commands were misidentified as reconnaissance. No executable code, no malicious patterns, no data exfiltration.
Факторы риска
⚙️ Внешние команды (98)
📁 Доступ к файловой системе (9)
10 янв. 2026 г., 14:17
Pure prompt-based skill with no executable code. Contains only documentation and instructions for writing PR descriptions using standard git/GitHub commands. No malicious patterns, data exfiltration, or suspicious network behavior detected.
10 янв. 2026 г., 14:17
Pure prompt-based skill with no executable code. Contains only documentation and instructions for writing PR descriptions using standard git/GitHub commands. No malicious patterns, data exfiltration, or suspicious network behavior detected.
10 янв. 2026 г., 14:17
Pure prompt-based skill with no executable code. Contains only documentation and instructions for writing PR descriptions using standard git/GitHub commands. No malicious patterns, data exfiltration, or suspicious network behavior detected.