Audit History
alibaba-java-coding-guidelines-skill - 4 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v4 Latest | Jul 6, 2026, 08:11 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 6, 2026, 08:11 PM | No confirmed findings | 0 | No capability change |
| v2 | Jun 30, 2026, 10:44 AM | No confirmed findings | 3 | No capability change |
| v1 | May 24, 2026, 03:17 PM | No confirmed findings | 0 | Baseline |
Jul 6, 2026, 08:11 PM
审计未发现恶意意图、提示注入、数据外泄或真实命令执行风险。静态告警主要来自 Markdown 反引号、Go 原始字符串、固定仓库文件读取、安装路径示例和中文文档高熵误报。
Risk Factors
📁 Filesystem access (8)
⚡ Contains scripts (1)
⚙️ External commands (21)
🌐 Network access (2)
Jul 6, 2026, 08:11 PM
审计未发现恶意意图、提示注入、数据外泄或真实命令执行风险。静态告警主要来自 Markdown 反引号、Go 原始字符串、固定仓库文件读取、安装路径示例和中文文档高熵误报。
Risk Factors
📁 Filesystem access (8)
⚡ Contains scripts (1)
⚙️ External commands (21)
🌐 Network access (2)
Jun 30, 2026, 10:44 AM
静态分析报告的高危项经人工语义核对后未确认恶意行为;多数来自 Markdown 反引号、Apache License 文本和 Java/SQL 术语误判。仓库包含本地校验脚本,会读取仓库文件并在测试脚本中运行本地验证器,因此保留低风险发布提示。未发现提示注入、凭据外发、远程下载执行或隐藏持久化证据。
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚡ Contains scripts (4)
📁 Filesystem access (4)
⚙️ External commands (2)
🌐 Network access (4)
Detected Patterns
May 24, 2026, 03:17 PM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.