Audit-Verlauf
doc-consistency-reviewer - 8 Audits
Versionsvergleich
Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.
| Version | Datum | Ergebnis | Prüfelemente | Änderung ggü. vorheriger |
|---|---|---|---|---|
| v8 Neueste | 6 июл. 2026 г., 14:25 | 1 bestätigt | 0 | Keine Änderung der Fähigkeiten |
| v7 | 6 июл. 2026 г., 14:25 | 1 bestätigt | 0 | Externe Befehle Dateisystemzugriff |
| v6 | 30 июн. 2026 г., 04:10 | 1 bestätigt | 0 | Dateisystemzugriff |
| v5 | 21 янв. 2026 г., 17:14 | Keine bestätigten Befunde | 0 | Externe Befehle |
| v4 | 17 янв. 2026 г., 06:32 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v3 | 17 янв. 2026 г., 06:32 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v2 | 11 янв. 2026 г., 05:58 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v1 | 11 янв. 2026 г., 05:58 | Keine bestätigten Befunde | 0 | Ausgangsbasis |
6 июл. 2026 г., 14:25
Static external-command findings are false positives from markdown fences, inline path formatting, and JSON strings. The entropy findings are false positives because the files are readable markdown. Semantic review found an embedded audit output file that claims the skill is safe and all findings are false positives.
Bestätigte Sicherheitsbedenken (1)
Risikofaktoren
⚙️ Externe Befehle (41)
6 июл. 2026 г., 14:25
Static external-command findings are false positives from markdown fences, inline path formatting, and JSON strings. The entropy findings are false positives because the files are readable markdown. Semantic review found an embedded audit output file that claims the skill is safe and all findings are false positives.
Bestätigte Sicherheitsbedenken (1)
Risikofaktoren
⚙️ Externe Befehle (41)
30 июн. 2026 г., 04:10
Static findings for shell backticks, weak cryptography, and obfuscation were evaluated as false positives from Markdown fences, example text, and multilingual documentation. No prompt injection, network access, executable script, or secret handling was found. The only retained risk is low because the skill asks the agent to write a local doc-consistency.md report.
Bestätigte Sicherheitsbedenken (1)
Statische falsch positive Treffer ignoriert (3)
Diese statischen Treffer wurden durch semantische Prüfung verworfen oder entsprachen reinen Schema-Tokens; daher werden sie aus Transparenzgründen angezeigt, beeinflussen jedoch nicht die Qualitätsbewertung.
Risikofaktoren
📁 Dateisystemzugriff (1)
21 янв. 2026 г., 17:14
All static findings are false positives. The 64 external_commands detections are markdown code blocks with shell examples in documentation, not executable code. The 17 weak_crypto detections are base64-encoded content in JSON/YAML files. The 9 obfuscation detections are high-entropy structured data patterns, not obfuscated payloads. Network detection is legitimate metadata (GitHub source URL). No actual security risks found.
17 янв. 2026 г., 06:32
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risikofaktoren
⚙️ Externe Befehle (64)
Erkannte Muster
17 янв. 2026 г., 06:32
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risikofaktoren
⚙️ Externe Befehle (64)
Erkannte Muster
11 янв. 2026 г., 05:58
This skill is a documentation review tool that analyzes markdown files and generates consistency reports. All static analysis findings were false positives - the 'external commands' were markdown code blocks showing example syntax, not actual code execution. The skill performs read-only operations on documentation files.
Risikofaktoren
⚙️ Externe Befehle (32)
11 янв. 2026 г., 05:58
This skill is a documentation review tool that analyzes markdown files and generates consistency reports. All static analysis findings were false positives - the 'external commands' were markdown code blocks showing example syntax, not actual code execution. The skill performs read-only operations on documentation files.