Audit History
Recipe Manager - 11 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v11 Latest | 18. Juli 2026, 09:59 | No confirmed findings | 0 | No capability change |
| v10 | 18. Juli 2026, 00:35 | 1 confirmed | 0 | No capability change |
| v9 | 7. Juli 2026, 18:58 | 1 confirmed | 0 | No capability change |
| v8 | 5. Juli 2026, 02:40 | 1 confirmed | 0 | External commands Filesystem access |
| v7 | 28. Juni 2026, 05:10 | No confirmed findings | 1 | Filesystem access |
| v6 | 21. Jan. 2026, 15:12 | No confirmed findings | 0 | External commands |
| v5 | 16. Jan. 2026, 16:33 | No confirmed findings | 0 | No capability change |
| v4 | 16. Jan. 2026, 16:33 | No confirmed findings | 0 | External commands |
| v3 | 10. Jan. 2026, 09:58 | No confirmed findings | 0 | No capability change |
| v2 | 10. Jan. 2026, 09:58 | No confirmed findings | 0 | No capability change |
| v1 | 10. Jan. 2026, 09:58 | No confirmed findings | 0 | Baseline |
18. Juli 2026, 09:59
All 57 static findings are false positives. The analyzer interpreted Markdown backticks and JavaScript template literals as shell execution, while the two reconnaissance matches are ordinary documentation. The skill contains recipe-data guidance only, with no executable commands, data exfiltration, or prompt-injection content found.
Risk Factors
⚙️ External commands (50)
18. Juli 2026, 00:35
All 57 static findings are false positives caused by Markdown backticks, JavaScript template literals, and ordinary application terminology. No shell execution, reconnaissance, prompt injection, credential access, network request, or exfiltration intent appears in SKILL.md. One low-severity semantic issue remains: the author-specific absolute recipes.js path can direct edits to an unintended location.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (50)
7. Juli 2026, 18:58
Static findings for shell execution and system reconnaissance are false positives caused by Markdown formatting, JavaScript examples, and project file references. No prompt injection, malware intent, or executable command path was found, but the skill includes a hard-coded local file path that should be removed before broad reuse.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (55)
5. Juli 2026, 02:40
The static command-execution findings are false positives caused by Markdown code fences, inline code formatting, and JavaScript template literals in SKILL.md. I found no prompt-injection language or malicious command intent. A low-severity issue remains because the skill documents an author-specific absolute local path.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (55)
28. Juni 2026, 05:10
AI review dismissed the static external command, weak cryptography, browser credential, and reconnaissance alerts as false positives from Markdown and JavaScript examples. One real concern remains: the skill directs agents to an author-specific absolute path, which can cause unintended filesystem edits outside a user project. No evidence found of malicious intent, prompt injection, credential access, network exfiltration, or executable shell commands.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (4)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
📁 Filesystem access (1)
Detected Patterns
21. Jan. 2026, 15:12
All static findings are false positives. The SKILL.md file contains documentation with JavaScript code examples for recipe management. Backtick patterns are markdown code fences, not shell execution. No actual filesystem access, network requests, or command execution occurs. This is a benign documentation skill for recipe data management.
16. Jan. 2026, 16:33
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
⚙️ External commands (84)
Detected Patterns
16. Jan. 2026, 16:33
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
⚙️ External commands (84)
Detected Patterns
10. Jan. 2026, 09:58
This is a pure documentation skill with no code execution, no file system access, no network calls, and no external commands. It only provides guidance to AI assistants on managing recipe data in recipes.js format.
10. Jan. 2026, 09:58
This is a pure documentation skill with no code execution, no file system access, no network calls, and no external commands. It only provides guidance to AI assistants on managing recipe data in recipes.js format.
10. Jan. 2026, 09:58
This is a pure documentation skill with no code execution, no file system access, no network calls, and no external commands. It only provides guidance to AI assistants on managing recipe data in recipes.js format.