審計歷史
blocklet-updater - 6 審計
審計版本 6
最新 中風險Jun 28, 2026, 10:23 AM
The static Ruby backtick and weak cryptography findings are false positives from markdown prose, inline code, and fenced command examples. The skill has a real medium-risk behavior because it instructs the agent to run blocklet and pnpm commands, including dependency installation and project build scripts, inside the user workspace.
中風險問題 (1)
低風險問題 (1)
風險因素
偵測到的模式
審計版本 5
安全Jan 16, 2026, 04:15 PM
This is a documentation-only skill containing workflow guidance for blocklet releases. No executable code, scripts, or network calls. Static findings are false positives: detected command patterns are bash examples in documentation, not shell execution; cryptographic algorithm warnings are pattern matches in JSON metadata; network detection is source URL in metadata. The skill only guides AI to run standard blocklet CLI commands in user projects.
風險因素
⚙️ 外部命令 (38)
審計版本 4
安全Jan 16, 2026, 04:15 PM
This is a documentation-only skill containing workflow guidance for blocklet releases. No executable code, scripts, or network calls. Static findings are false positives: detected command patterns are bash examples in documentation, not shell execution; cryptographic algorithm warnings are pattern matches in JSON metadata; network detection is source URL in metadata. The skill only guides AI to run standard blocklet CLI commands in user projects.
風險因素
⚙️ 外部命令 (38)
審計版本 3
安全Jan 10, 2026, 10:23 AM
This is a prompt-based skill containing only documentation files. No executable code, scripts, or network calls. The skill provides workflow guidance for the AI to execute standard blocklet CLI commands in the user's project directory.
審計版本 2
安全Jan 10, 2026, 10:23 AM
This is a prompt-based skill containing only documentation files. No executable code, scripts, or network calls. The skill provides workflow guidance for the AI to execute standard blocklet CLI commands in the user's project directory.
審計版本 1
安全Jan 10, 2026, 10:23 AM
This is a prompt-based skill containing only documentation files. No executable code, scripts, or network calls. The skill provides workflow guidance for the AI to execute standard blocklet CLI commands in the user's project directory.