История аудитов
htmx-skill - 8 аудиты
Сравнение версий
Изменения возможностей и находок между проверенными версиями, сначала новые.
| Версия | Дата | Результат | Пункты проверки | Изменение к предыдущей |
|---|---|---|---|---|
| v8 Последняя | 5 июл. 2026 г., 13:39 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v7 | 5 июл. 2026 г., 13:39 | Подтверждённых находок нет | 0 | Внешние команды |
| v6 | 29 июн. 2026 г., 21:28 | 3 подтверждено | 1 | Содержит скрипты |
| v5 | 17 янв. 2026 г., 04:25 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v4 | 17 янв. 2026 г., 04:25 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v3 | 10 янв. 2026 г., 14:25 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v2 | 10 янв. 2026 г., 14:25 | Подтверждённых находок нет | 0 | Возможности не изменились |
| v1 | 10 янв. 2026 г., 14:25 | Подтверждённых находок нет | 0 | Базовая |
5 июл. 2026 г., 13:39
AI review found no evidence of malicious intent, prompt injection, credential theft, or unauthorized execution. The static findings are false positives from htmx documentation examples, Markdown formatting, license URLs, and a scoped manual builder script.
Факторы риска
🌐 Доступ к сети (55)
📁 Доступ к файловой системе (4)
⚡ Содержит скрипты (4)
⚙️ Внешние команды (28)
5 июл. 2026 г., 13:39
AI review found no evidence of malicious intent, prompt injection, credential theft, or unauthorized execution. The static findings are false positives from htmx documentation examples, Markdown formatting, license URLs, and a scoped manual builder script.
Факторы риска
🌐 Доступ к сети (55)
📁 Доступ к файловой системе (4)
⚡ Содержит скрипты (4)
⚙️ Внешние команды (28)
29 июн. 2026 г., 21:28
Static analysis produced a very high score because it treated markdown documentation, htmx API names, and example snippets as executable behavior. Review found no prompt injection attempt, no malicious intent, and no confirmed command execution or credential exfiltration. The remaining risk is medium because the optional builder downloads and rewrites documentation files, and some examples document browser-side patterns that require careful security handling.
Подтверждённые проблемы безопасности (3)
Пункты проверки возможностей (1)
Это реальные локальные возможности, которые могут ожидаться для этого навыка, поэтому они требуют проверки, но не считаются подтверждённым вредоносным поведением.
Статические ложные срабатывания проигнорированы (1)
Эти статические совпадения были отклонены семантической проверкой или совпадали только со схемными токенами, поэтому они показываются для прозрачности, но не влияют на оценку качества.
Факторы риска
🌐 Доступ к сети (3)
📁 Доступ к файловой системе (3)
Обнаруженные паттерны
17 янв. 2026 г., 04:25
This is a pure documentation/reference skill containing markdown files and a build script. The 2454 static findings are 99%+ false positives. The 'Ruby/shell backtick execution' findings are markdown code formatting. 'Weak cryptographic algorithm' findings are regex false positives from documentation text. Network/filesystem operations are for downloading documentation from GitHub. No malicious patterns detected.
Факторы риска
🌐 Доступ к сети (2)
📁 Доступ к файловой системе (2)
17 янв. 2026 г., 04:25
This is a pure documentation/reference skill containing markdown files and a build script. The 2454 static findings are 99%+ false positives. The 'Ruby/shell backtick execution' findings are markdown code formatting. 'Weak cryptographic algorithm' findings are regex false positives from documentation text. Network/filesystem operations are for downloading documentation from GitHub. No malicious patterns detected.
Факторы риска
🌐 Доступ к сети (2)
📁 Доступ к файловой системе (2)
10 янв. 2026 г., 14:25
This is a pure documentation/reference skill containing only markdown files and a Python build script. The Python script is a development utility that downloads documentation from the official htmx GitHub repository and is not executed at runtime. No malicious code patterns detected.
Факторы риска
🌐 Доступ к сети (2)
📁 Доступ к файловой системе (2)
10 янв. 2026 г., 14:25
This is a pure documentation/reference skill containing only markdown files and a Python build script. The Python script is a development utility that downloads documentation from the official htmx GitHub repository and is not executed at runtime. No malicious code patterns detected.
Факторы риска
🌐 Доступ к сети (2)
📁 Доступ к файловой системе (2)
10 янв. 2026 г., 14:25
This is a pure documentation/reference skill containing only markdown files and a Python build script. The Python script is a development utility that downloads documentation from the official htmx GitHub repository and is not executed at runtime. No malicious code patterns detected.