Навыки onboard История аудитов
📦

История аудитов

onboard - 4 аудиты

Сравнение версий

Изменения возможностей и находок между проверенными версиями, сначала новые.

ВерсияДатаРезультатПункты проверкиИзменение к предыдущей
v4 Последняя6 июл. 2026 г., 20:30 Подтверждённых находок нет0Возможности не изменились
v3 6 июл. 2026 г., 20:30 Подтверждённых находок нет0Внешние команды
v2 30 июн. 2026 г., 11:34 2 подтверждено0Возможности не изменились
v1 16 мар. 2026 г., 08:34 Подтверждённых находок нет0Базовая
Версия аудита 4 Последняя

6 июл. 2026 г., 20:30

The static findings are false positives caused by Markdown code fences, inline Markdown formatting, and UX guidance in SKILL.md. I found no evidence of shell execution, system reconnaissance, data exfiltration, prompt injection, or malicious intent in the reviewed file.

1
Просканировано файлов
250
Проанализировано строк
1
Пункты проверки
0
Ложные срабатывания проигнорированы

Факторы риска

Аудитор:: codex

6 июл. 2026 г., 20:30

The static findings are false positives caused by Markdown code fences, inline Markdown formatting, and UX guidance in SKILL.md. I found no evidence of shell execution, system reconnaissance, data exfiltration, prompt injection, or malicious intent in the reviewed file.

1
Просканировано файлов
250
Проанализировано строк
1
Пункты проверки
0
Ложные срабатывания проигнорированы

Факторы риска

Аудитор:: codex

30 июн. 2026 г., 11:34

Static analysis reported command execution, weak cryptography, browser storage, and reconnaissance patterns. Review found the command, crypto, and reconnaissance hits are markdown or natural-language false positives. LocalStorage appears only as benign onboarding-state guidance, so the skill is safe to publish with a minor privacy caution.

1
Просканировано файлов
250
Проанализировано строк
2
Пункты проверки
2
Ложные срабатывания проигнорированы

Подтверждённые проблемы безопасности (2)

Низкий
Browser Storage Guidance Stores Only Onboarding State
Verdict: FALSE_POSITIVE for sensitive data exposure. The LocalStorage examples store completion and tooltip-seen flags only. This is not credential storage, but implementers should avoid storing personal data or secrets in browser storage.
The examples use fixed onboarding keys with boolean-like values. There is no evidence of tokens, credentials, profile data, or exfiltration.
Низкий
System Reconnaissance Finding Is Validation Guidance
Verdict: FALSE_POSITIVE. The reported line asks designers to validate whether a user completed an onboarding task correctly. No evidence found of host enumeration, system probing, or environment discovery.
The matched text is a product onboarding checklist item. It is unrelated to system reconnaissance or local machine inspection.
Статические ложные срабатывания проигнорированы (2)

Эти статические совпадения были отклонены семантической проверкой или совпадали только со схемными токенами, поэтому они показываются для прозрачности, но не влияют на оценку качества.

Низкий
Static External Command Findings Are Markdown False Positives
Verdict: FALSE_POSITIVE. The reported backtick execution locations are markdown code fences or inline UI examples, not executable Ruby or shell commands. No evidence found of command execution instructions or user-controlled shell input.
The matched lines are visible as markdown delimiters or inline keyboard and help text. They do not invoke a shell, interpreter, or external process.
Низкий
Weak Cryptography Findings Are Natural-Language False Positives
Verdict: FALSE_POSITIVE. The weak cryptography detector appears to match text such as design-related wording, headings, and UX guidance. No evidence found of DES, MD5, SHA-1, encryption code, hashing code, or cryptographic configuration.
The skill is a prose design guide and contains no cryptographic API usage. The reported lines are headings or UX instructions.
Аудитор:: codex

16 мар. 2026 г., 08:34

Static analysis detected 22 potential security issues, all confirmed as false positives after manual review. The skill file contains only Markdown documentation with code examples demonstrating UX patterns. No executable code or security risks present.

1
Просканировано файлов
250
Проанализировано строк
0
Пункты проверки
0
Ложные срабатывания проигнорированы
В этом завершенном аудите не зафиксировано подтвержденных проблем безопасности.
Аудитор:: claude