Навыки vue-testing-best-practices История аудитов
📦

История аудитов

vue-testing-best-practices - 4 аудиты

Сравнение версий

Изменения возможностей и находок между проверенными версиями, сначала новые.

ВерсияДатаРезультатПункты проверкиИзменение к предыдущей
v4 Последняя7 июл. 2026 г., 07:07 Подтверждённых находок нет0Возможности не изменились
v3 7 июл. 2026 г., 07:07 Подтверждённых находок нет0Возможности не изменились
v2 30 июн. 2026 г., 23:04 1 подтверждено3Содержит скриптыВнешние командыДоступ к сетиПеременные окружения
v1 11 февр. 2026 г., 09:15 Подтверждённых находок нет0Базовая
Версия аудита 4 Последняя

7 июл. 2026 г., 07:07

I found no evidence of malicious intent or prompt injection. The static findings are false positives from documentation examples: local dynamic imports, CI flags, localhost URLs, and Markdown backticks. No remediation is required before publication from this audit.

12
Просканировано файлов
2,227
Проанализировано строк
4
Пункты проверки
0
Ложные срабатывания проигнорированы
Аудитор:: codex

7 июл. 2026 г., 07:07

I found no evidence of malicious intent or prompt injection. The static findings are false positives from documentation examples: local dynamic imports, CI flags, localhost URLs, and Markdown backticks. No remediation is required before publication from this audit.

12
Просканировано файлов
2,227
Проанализировано строк
4
Пункты проверки
0
Ложные срабатывания проигнорированы
Аудитор:: codex

30 июн. 2026 г., 23:04

Static analysis reported many dynamic import, command, URL, environment, and weak-crypto patterns, but review shows they are documentation examples for Vue testing. The files contain Markdown guidance, local development commands, CI flag examples, and official documentation links; no prompt injection, malicious execution, credential exfiltration, or hidden network behavior was found.

12
Просканировано файлов
2,227
Проанализировано строк
8
Пункты проверки
1
Ложные срабатывания проигнорированы

Подтверждённые проблемы безопасности (1)

Низкий
Weak cryptography findings are text-pattern matches
Verdict: FALSE_POSITIVE. The weak-crypto alerts align with frontmatter, impact descriptions, and ordinary Vue testing prose rather than cryptographic APIs. No evidence found of MD5, SHA-1, insecure random generation, or password hashing code.
Targeted review found testing descriptions at the flagged locations, not cryptographic operations. A repository search found no evidence of cryptographic implementation code.
Пункты проверки возможностей (3)

Это реальные локальные возможности, которые могут ожидаться для этого навыка, поэтому они требуют проверки, но не считаются подтверждённым вредоносным поведением.

Низкий
Dynamic imports are Vue async component examples
Verdict: FALSE_POSITIVE. The import() expressions appear inside Markdown examples that teach testing of defineAsyncComponent and Suspense. They load local Vue component paths in illustrative test code, not untrusted input or marketplace runtime code.
The locations are within documentation examples about Vue async components. No evidence shows dynamic import of user-controlled paths or execution by the skill itself.
Низкий
Command patterns are testing setup snippets
Verdict: FALSE_POSITIVE. The command-like content is standard Vue testing documentation, including package installation, package.json test scripts, and Playwright development commands. These examples may ask users to run normal project tooling, but they do not execute automatically or hide unsafe shell behavior.
The examples use common npm, npx, Vitest, and Playwright commands for test setup. There is no evidence of command injection, remote script download, or obfuscated execution.
Низкий
Environment access is limited to CI flags
Verdict: FALSE_POSITIVE. The process.env examples only inspect the CI flag to adjust retries, workers, server reuse, and Vitest threading. They do not read secret variables, environment files, tokens, or credentials.
The only observed environment variable is process.env.CI in test configuration examples. No evidence found of .env file parsing, credential access, or network transmission.
Статические ложные срабатывания проигнорированы (1)

Эти статические совпадения были отклонены семантической проверкой или совпадали только со схемными токенами, поэтому они показываются для прозрачности, но не влияют на оценку качества.

Низкий
Hardcoded URLs are documentation links or localhost
Verdict: FALSE_POSITIVE. The URL findings point to official Vue, Vue Test Utils, Vitest, Playwright, Pinia, and local development server references. They are citations or localhost test configuration values, not outbound exfiltration endpoints.
The URLs are visible references or localhost values used by Playwright examples. No evidence found of requests that transmit user data or secrets.
Аудитор:: codex

11 февр. 2026 г., 09:15

All static findings are false positives. This is a documentation skill containing Vue.js testing best practices. The scanner misinterpreted markdown code examples and Vite configuration patterns as security threats. No malicious code, credential access, or data exfiltration patterns exist.

12
Просканировано файлов
2,227
Проанализировано строк
0
Пункты проверки
0
Ложные срабатывания проигнорированы
В этом завершенном аудите не зафиксировано подтвержденных проблем безопасности.
Аудитор:: claude