📚

審計歷史

literature-review - 4 審計

審計版本 4

最新 低風險

Jan 17, 2026, 06:14 AM

This literature-review skill is a legitimate academic research tool. Static analysis flagged 178 potential security issues, but all findings are false positives. The external_command patterns are documentation examples of standard academic tools (pandoc, xelatex, gget). Network requests target legitimate academic APIs (CrossRef, DOI resolution, PubMed). Filesystem operations write search results and verification reports. No malicious intent, data exfiltration, or command injection vectors detected.

8
已掃描檔案
2,637
分析行數
3
發現項
claude
審計者
未發現安全問題

風險因素

⚙️ 外部命令 (1)
🌐 網路存取 (1)
📁 檔案系統存取 (1)

審計版本 3

低風險

Jan 17, 2026, 06:14 AM

This literature-review skill is a legitimate academic research tool. Static analysis flagged 178 potential security issues, but all findings are false positives. The external_command patterns are documentation examples of standard academic tools (pandoc, xelatex, gget). Network requests target legitimate academic APIs (CrossRef, DOI resolution, PubMed). Filesystem operations write search results and verification reports. No malicious intent, data exfiltration, or command injection vectors detected.

8
已掃描檔案
2,637
分析行數
3
發現項
claude
審計者
未發現安全問題

風險因素

⚙️ 外部命令 (1)
🌐 網路存取 (1)
📁 檔案系統存取 (1)

審計版本 2

低風險

Jan 12, 2026, 04:55 PM

The literature-review skill is a legitimate academic research tool. Static analysis flagged many external_command patterns, but these are documentation examples showing shell commands for legitimate tools (pandoc, gget). The network requests are to standard academic APIs (CrossRef, DOI resolution) and database services. No malicious intent detected.

7
已掃描檔案
2,374
分析行數
3
發現項
claude
審計者
未發現安全問題

風險因素

⚙️ 外部命令 (1)
🌐 網路存取 (1)
📁 檔案系統存取 (1)

審計版本 1

中風險

Jan 4, 2026, 04:53 PM

This skill contains Python scripts that process user files and make HTTP requests to public DOI and CrossRef APIs for citation verification. The scripts invoke local tools (pandoc, xelatex) for PDF generation. No sensitive file access, environment harvesting, credential theft, or data exfiltration patterns were detected. The network activity is limited to legitimate academic API endpoints.

10
已掃描檔案
2,530
分析行數
3
發現項
claude
審計者
未發現安全問題