Навыки data-engineer История аудитов
📦

История аудитов

data-engineer - 4 аудиты

Сравнение версий

Изменения возможностей и находок между проверенными версиями, сначала новые.

ВерсияДатаРезультатПункты проверкиИзменение к предыдущей
v4 Последняя23 июл. 2026 г., 23:28 1 подтверждено0Возможности не изменились
v3 15 июл. 2026 г., 15:03 2 подтверждено0Возможности не изменились
v2 15 июл. 2026 г., 15:03 2 подтверждено0Возможности не изменились
v1 15 июл. 2026 г., 15:03 2 подтверждено0Базовая
Версия аудита 4 Последняя

23 июл. 2026 г., 23:28

All 42 backtick detections are Markdown fences or inline code, not shell execution. Eight reconnaissance matches are schema identifiers, and multilingual diagrams explain the entropy alert. Destructive delete and overwrite examples still lack confirmation, backup, and environment safeguards.

1
Просканировано файлов
1,058
Проанализировано строк
2
Пункты проверки
0
Ложные срабатывания проигнорированы

Подтверждённые проблемы безопасности (1)

Средний
Destructive Data Operations Lack Guardrails
The command reference shows an ALTER TABLE DELETE, and the PySpark template uses overwrite mode. Neither example requires confirmation, backup verification, or a dry run.
Both destructive operations appear directly in reusable examples, with no adjacent safety gate. The placeholder targets reduce immediate impact but not reuse risk.
Аудитор:: codex

15 июл. 2026 г., 15:03

All 51 static findings are false positives caused by Markdown formatting, SQL identifiers, multilingual text, and documentation examples. No prompt injection, hidden executable payload, or obfuscation was found. Operational examples can still delete or overwrite data without explicit confirmation safeguards.

1
Просканировано файлов
1,058
Проанализировано строк
3
Пункты проверки
0
Ложные срабатывания проигнорированы

Подтверждённые проблемы безопасности (2)

Средний
Destructive Operations Lack Confirmation Safeguards
The command reference includes a database delete, and the PySpark template uses overwrite mode. The skill does not require confirmation, backups, or dry runs before these actions.
Both destructive patterns are explicit examples, and surrounding guidance directs the agent to deploy and run pipelines. Risk depends on access to live systems.
Низкий
Inline Credential Pattern in JDBC Example
The JDBC example places username and password values directly in pipeline code. Although placeholders, this pattern can encourage users to embed real credentials.
The username and password options are visibly embedded in the example. They are placeholders, so no actual secret exposure is present.

Факторы риска

⚙️ Внешние команды (1)
Аудитор:: codex

15 июл. 2026 г., 15:03

All 51 static findings are false positives caused by Markdown formatting, SQL identifiers, multilingual text, and documentation examples. No prompt injection, hidden executable payload, or obfuscation was found. Operational examples can still delete or overwrite data without explicit confirmation safeguards.

1
Просканировано файлов
1,058
Проанализировано строк
3
Пункты проверки
0
Ложные срабатывания проигнорированы

Подтверждённые проблемы безопасности (2)

Средний
Destructive Operations Lack Confirmation Safeguards
The command reference includes a database delete, and the PySpark template uses overwrite mode. The skill does not require confirmation, backups, or dry runs before these actions.
Both destructive patterns are explicit examples, and surrounding guidance directs the agent to deploy and run pipelines. Risk depends on access to live systems.
Низкий
Inline Credential Pattern in JDBC Example
The JDBC example places username and password values directly in pipeline code. Although placeholders, this pattern can encourage users to embed real credentials.
The username and password options are visibly embedded in the example. They are placeholders, so no actual secret exposure is present.

Факторы риска

⚙️ Внешние команды (1)
Аудитор:: codex

15 июл. 2026 г., 15:03

All 51 static findings are false positives caused by Markdown formatting, SQL identifiers, multilingual text, and documentation examples. No prompt injection, hidden executable payload, or obfuscation was found. Operational examples can still delete or overwrite data without explicit confirmation safeguards.

1
Просканировано файлов
1,058
Проанализировано строк
3
Пункты проверки
0
Ложные срабатывания проигнорированы

Подтверждённые проблемы безопасности (2)

Средний
Destructive Operations Lack Confirmation Safeguards
The command reference includes a database delete, and the PySpark template uses overwrite mode. The skill does not require confirmation, backups, or dry runs before these actions.
Both destructive patterns are explicit examples, and surrounding guidance directs the agent to deploy and run pipelines. Risk depends on access to live systems.
Низкий
Inline Credential Pattern in JDBC Example
The JDBC example places username and password values directly in pipeline code. Although placeholders, this pattern can encourage users to embed real credentials.
The username and password options are visibly embedded in the example. They are placeholders, so no actual secret exposure is present.

Факторы риска

⚙️ Внешние команды (1)
Аудитор:: codex