審計紀錄
ffind - 6 審計
審計版本 6
最新 高風險Jun 28, 2026, 06:01 PM
The static external command and sudo findings are true positives because the skill instructs agents to run ffind on user-supplied paths and use sudo for extraction. The temp directory findings are also real, while the weak cryptography findings are false positives from filesystem version text, not cryptographic code. No prompt injection or confirmed malicious intent was found, so the skill is not blocked but should not publish without human review and stronger safety guidance.
高風險問題 (1)
中風險問題 (2)
低風險問題 (1)
風險因素
⚙️ 外部命令 (8)
📁 檔案系統存取 (2)
偵測到的模式
審計版本 5
安全Jan 16, 2026, 07:58 PM
This is a documentation-only skill containing markdown instructions for the external ffind CLI tool. No executable code, network calls, or file system operations exist within the skill itself. All 41 static findings are false positives triggered by documentation patterns: sudo mentions document tool requirements, backticks are markdown code formatting, filesystem type identifiers (ext2/3/4) were misidentified as cryptographic algorithms, and temp directory references are documentation of tool behavior.
風險因素
⚙️ 外部命令 (21)
📁 檔案系統存取 (2)
審計版本 4
安全Jan 16, 2026, 07:58 PM
This is a documentation-only skill containing markdown instructions for the external ffind CLI tool. No executable code, network calls, or file system operations exist within the skill itself. All 41 static findings are false positives triggered by documentation patterns: sudo mentions document tool requirements, backticks are markdown code formatting, filesystem type identifiers (ext2/3/4) were misidentified as cryptographic algorithms, and temp directory references are documentation of tool behavior.
風險因素
⚙️ 外部命令 (21)
📁 檔案系統存取 (2)
審計版本 3
安全Jan 10, 2026, 11:32 AM
Pure prompt-based skill containing only documentation and usage instructions. No executable code, no file system access, no network calls, and no external command execution within the skill itself.
審計版本 2
安全Jan 10, 2026, 11:32 AM
Pure prompt-based skill containing only documentation and usage instructions. No executable code, no file system access, no network calls, and no external command execution within the skill itself.
審計版本 1
安全Jan 10, 2026, 11:32 AM
Pure prompt-based skill containing only documentation and usage instructions. No executable code, no file system access, no network calls, and no external command execution within the skill itself.