سجل التدقيق
mastra - 4 عمليات التدقيق
مقارنة الإصدارات
التغييرات في القدرات والنتائج عبر الإصدارات المدقّقة، الأحدث أولاً.
| الإصدار | التاريخ | النتيجة | عناصر المراجعة | التغيير مقارنةً بالسابقة |
|---|---|---|---|---|
| v4 الأحدث | 5 июл. 2026 г., 19:43 | 1 مؤكَّد | 0 | لا تغيير في القدرات |
| v3 | 5 июл. 2026 г., 19:43 | 1 مؤكَّد | 0 | لا تغيير في القدرات |
| v2 | 30 июн. 2026 г., 07:46 | لا توجد نتائج مؤكَّدة | 3 | الأوامر الخارجيةالوصول إلى الشبكةمتغيرات البيئةالوصول إلى نظام الملفات |
| v1 | 15 февр. 2026 г., 08:42 | لا توجد نتائج مؤكَّدة | 0 | الأساس |
5 июл. 2026 г., 19:43
Static findings are almost entirely documentation examples, Markdown formatting, official documentation URLs, localhost references, or placeholder environment variable usage. I found no prompt injection or hidden execution logic, but the setup guide does encourage users to provide an API key to the AI agent, which is a real secret-handling risk.
مخاوف أمنية مؤكدة (1)
عوامل الخطر
⚙️ الأوامر الخارجية (35)
🌐 الوصول إلى الشبكة (17)
🔑 متغيرات البيئة (18)
📁 الوصول إلى نظام الملفات (1)
5 июл. 2026 г., 19:43
Static findings are almost entirely documentation examples, Markdown formatting, official documentation URLs, localhost references, or placeholder environment variable usage. I found no prompt injection or hidden execution logic, but the setup guide does encourage users to provide an API key to the AI agent, which is a real secret-handling risk.
مخاوف أمنية مؤكدة (1)
عوامل الخطر
⚙️ الأوامر الخارجية (35)
🌐 الوصول إلى الشبكة (17)
🔑 متغيرات البيئة (18)
📁 الوصول إلى نظام الملفات (1)
30 июн. 2026 г., 07:46
Static analysis reported many command, network, filesystem, and secret-related patterns, but review found them in Markdown setup and troubleshooting examples rather than executable skill code. The skill is publishable with a medium warning because it guides package installation, project file creation, local documentation reads, remote documentation fetches, and API key configuration.
عناصر مراجعة القدرات (3)
هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.
تم تجاهل الإيجابيات الكاذبة الثابتة (1)
تم تجاهل هذه المطابقات الثابتة بواسطة المراجعة الدلالية أو لأنها طابقت رموزًا خاصة بالمخطط فقط، لذا تُعرض للشفافية لكنها لا تؤثر في درجة الجودة.
عوامل الخطر
⚙️ الأوامر الخارجية (4)
🌐 الوصول إلى الشبكة (3)
🔑 متغيرات البيئة (3)
📁 الوصول إلى نظام الملفات (3)
الأنماط المكتشفة
15 февр. 2026 г., 08:42
This is a documentation/reference skill providing guidance on the Mastra framework. All static findings are false positives: (1) Backtick patterns are markdown code block delimiters in documentation, not shell commands. (2) Hardcoded URLs are legitimate documentation links. (3) Environment variable patterns are code examples showing configuration. (4) Cryptographic references are documentation content. No actual security risks present.