審計歷史
frontend-dev - 2 審計
審計版本 2
最新 中風險May 27, 2026, 06:26 PM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
風險因素
🌐 網路存取 (73)
⚙️ 外部命令 (841)
🔑 環境變數 (51)
📁 檔案系統存取 (16)
⚡ 包含腳本 (1)
偵測到的模式
審計版本 1
低風險Apr 16, 2026, 06:14 AM
Static analysis flagged 1176 patterns with a risk score of 100/100, but evaluation confirms these are overwhelmingly false positives. High-severity 'weak cryptographic algorithm' findings in canvas-fonts/*.txt files are font Open Font License texts, not crypto code. 'Ruby/shell backtick execution' findings in markdown reference files are backtick-enclosed code examples in documentation. 'Windows SAM database' finding at templates/viewer.html:508 is the word 'CUSTOMIZE' containing the substring 'SAM'. regex.exec() in generator_template.js:133 is a standard JavaScript hex color parser. The skill is a legitimate frontend development tool with MiniMax API client scripts that properly use environment variables for API key management. Low risk after review.