審計紀錄
bodhi-sdk-react-integration - 6 審計
審計版本 6
最新 中風險Jun 28, 2026, 04:06 PM
Static analysis heavily overcounted Markdown code fences as Ruby backtick execution and marked documentation URLs as risky network behavior. Human review found no prompt injection or confirmed malicious intent, but the skill can run npm/npx commands and includes troubleshooting guidance that may expose OAuth token state in browser storage or console logs.
中風險問題 (2)
低風險問題 (3)
風險因素
⚙️ 外部命令 (6)
🌐 網路存取 (5)
🔑 環境變數 (5)
📁 檔案系統存取 (3)
偵測到的模式
審計版本 5
安全Jan 16, 2026, 07:07 PM
Documentation-only skill providing step-by-step guidance for integrating bodhi-js-sdk into React applications. All 438 static findings are false positives: the scanner misinterprets markdown code block delimiters (triple backticks) as Ruby shell backtick execution, legitimate Bodhi SDK endpoints as hardcoded network targets, and standard Vite environment variable patterns as sensitive data access. No executable code exists - only markdown documentation files (.md) with code examples for user reference.
風險因素
⚙️ 外部命令 (288)
🌐 網路存取 (70)
審計版本 4
安全Jan 16, 2026, 07:07 PM
Documentation-only skill providing step-by-step guidance for integrating bodhi-js-sdk into React applications. All 438 static findings are false positives: the scanner misinterprets markdown code block delimiters (triple backticks) as Ruby shell backtick execution, legitimate Bodhi SDK endpoints as hardcoded network targets, and standard Vite environment variable patterns as sensitive data access. No executable code exists - only markdown documentation files (.md) with code examples for user reference.
風險因素
⚙️ 外部命令 (288)
🌐 網路存取 (70)
審計版本 3
安全Jan 10, 2026, 11:27 AM
Documentation-only skill providing guidance for integrating bodhi-js-sdk into React applications. No executable code present. All described capabilities are standard web development practices for LLM SDK integration.
審計版本 2
安全Jan 10, 2026, 11:27 AM
Documentation-only skill providing guidance for integrating bodhi-js-sdk into React applications. No executable code present. All described capabilities are standard web development practices for LLM SDK integration.
審計版本 1
安全Jan 10, 2026, 11:27 AM
Documentation-only skill providing guidance for integrating bodhi-js-sdk into React applications. No executable code present. All described capabilities are standard web development practices for LLM SDK integration.