Audit History
code-consistency-validator - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | 6. Juli 2026, 03:15 | No confirmed findings | 0 | No capability change |
| v7 | 6. Juli 2026, 03:15 | No confirmed findings | 0 | No capability change |
| v6 | 28. Juni 2026, 14:06 | No confirmed findings | 1 | No capability change |
| v5 | 16. Jan. 2026, 17:38 | No confirmed findings | 0 | No capability change |
| v4 | 16. Jan. 2026, 17:38 | No confirmed findings | 0 | External commands |
| v3 | 10. Jan. 2026, 10:57 | No confirmed findings | 0 | No capability change |
| v2 | 10. Jan. 2026, 10:57 | No confirmed findings | 0 | No capability change |
| v1 | 10. Jan. 2026, 10:57 | No confirmed findings | 0 | Baseline |
6. Juli 2026, 03:15
The three static findings are false positives caused by Markdown code fences, not executable Ruby backtick shell calls. SKILL.md includes benign grep examples for local review and no evidence of prompt injection or data exfiltration.
Risk Factors
⚙️ External commands (3)
6. Juli 2026, 03:15
The three static findings are false positives caused by Markdown code fences, not executable Ruby backtick shell calls. SKILL.md includes benign grep examples for local review and no evidence of prompt injection or data exfiltration.
Risk Factors
⚙️ External commands (3)
28. Juni 2026, 14:06
Static shell backtick findings are false positives caused by Markdown code fences and local grep examples. The weak cryptographic algorithm finding at SKILL.md:3 is also a false positive; no cryptographic algorithm is present. The skill has low risk because it suggests local grep commands but shows no network, secret access, destructive action, or prompt injection.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (1)
16. Jan. 2026, 17:38
All 12 static findings are FALSE_POSITIVES. This is a prompt-only documentation skill containing only markdown guidance and example grep commands. No executable code, network calls, filesystem access, environment variable reads, or external command execution exists. Static scanner flagged JSON metadata fields, documentation text, and markdown code examples as security patterns out of context.
Risk Factors
⚙️ External commands (3)
16. Jan. 2026, 17:38
All 12 static findings are FALSE_POSITIVES. This is a prompt-only documentation skill containing only markdown guidance and example grep commands. No executable code, network calls, filesystem access, environment variable reads, or external command execution exists. Static scanner flagged JSON metadata fields, documentation text, and markdown code examples as security patterns out of context.
Risk Factors
⚙️ External commands (3)
10. Jan. 2026, 10:57
This is a prompt-only documentation skill with no executable code. It provides type validation guidance and grep patterns for reviewing code. No files scanned contain scripts, network calls, filesystem access, environment variable reads, or external command execution.
10. Jan. 2026, 10:57
This is a prompt-only documentation skill with no executable code. It provides type validation guidance and grep patterns for reviewing code. No files scanned contain scripts, network calls, filesystem access, environment variable reads, or external command execution.
10. Jan. 2026, 10:57
This is a prompt-only documentation skill with no executable code. It provides type validation guidance and grep patterns for reviewing code. No files scanned contain scripts, network calls, filesystem access, environment variable reads, or external command execution.