📋

审计历史

app-store-changelog - 5 审计

审计版本 5

最新 安全

Jan 17, 2026, 03:53 AM

All 27 static findings are FALSE_POSITIVES. This is a legitimate changelog generation tool. The scanner misidentified: git command outputs as 'weak cryptographic algorithms', standard git operations as 'system reconnaissance', markdown code formatting as 'shell backtick execution', and a GitHub repository URL as 'hardcoded URL'. The bash script only executes predefined git commands (log, describe, rev-parse) with hardcoded arguments. No network access beyond reading local git repository. No command injection vectors or arbitrary code execution.

4
已扫描文件
357
分析行数
3
发现项
claude
审计者
未发现安全问题

审计版本 4

安全

Jan 17, 2026, 03:53 AM

All 27 static findings are FALSE_POSITIVES. This is a legitimate changelog generation tool. The scanner misidentified: git command outputs as 'weak cryptographic algorithms', standard git operations as 'system reconnaissance', markdown code formatting as 'shell backtick execution', and a GitHub repository URL as 'hardcoded URL'. The bash script only executes predefined git commands (log, describe, rev-parse) with hardcoded arguments. No network access beyond reading local git repository. No command injection vectors or arbitrary code execution.

4
已扫描文件
357
分析行数
3
发现项
claude
审计者
未发现安全问题

审计版本 3

低风险

Jan 10, 2026, 02:01 PM

This skill contains a bash script that reads git history to generate release notes. It only executes predefined git commands for collecting commit metadata and file lists. No network access, no arbitrary code execution, no sensitive data access. Minimal risk tool for changelog generation.

3
已扫描文件
110
分析行数
3
发现项
claude
审计者
未发现安全问题

审计版本 2

低风险

Jan 10, 2026, 02:01 PM

This skill contains a bash script that reads git history to generate release notes. It only executes predefined git commands for collecting commit metadata and file lists. No network access, no arbitrary code execution, no sensitive data access. Minimal risk tool for changelog generation.

3
已扫描文件
110
分析行数
3
发现项
claude
审计者
未发现安全问题

审计版本 1

低风险

Jan 10, 2026, 02:01 PM

This skill contains a bash script that reads git history to generate release notes. It only executes predefined git commands for collecting commit metadata and file lists. No network access, no arbitrary code execution, no sensitive data access. Minimal risk tool for changelog generation.

3
已扫描文件
110
分析行数
3
发现项
claude
审计者
未发现安全问题