Audit History
property-testing-guide - 4 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v4 Latest | 6 июл. 2026 г., 15:19 | No confirmed findings | 0 | No capability change |
| v3 | 6 июл. 2026 г., 15:19 | No confirmed findings | 0 | External commands |
| v2 | 29 июн. 2026 г., 23:05 | No confirmed findings | 0 | No capability change |
| v1 | 23 янв. 2026 г., 02:31 | No confirmed findings | 0 | Baseline |
6 июл. 2026 г., 15:19
All static findings are false positives from Markdown code fences, Rust examples, TOML dependency text, and ordinary proptest comments. No prompt injection, malicious intent, command execution, data exfiltration, or system reconnaissance was found in SKILL.md.
Risk Factors
⚙️ External commands (27)
6 июл. 2026 г., 15:19
All static findings are false positives from Markdown code fences, Rust examples, TOML dependency text, and ordinary proptest comments. No prompt injection, malicious intent, command execution, data exfiltration, or system reconnaissance was found in SKILL.md.
Risk Factors
⚙️ External commands (27)
29 июн. 2026 г., 23:05
Static analysis reported external command, weak cryptography, and system reconnaissance patterns in SKILL.md. Manual review found documentation-only Rust and TOML examples, with no executable shell commands, cryptographic code, reconnaissance behavior, network access, or prompt injection attempts. The skill is safe to publish with low residual risk from community-sourced instructional content.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
23 янв. 2026 г., 02:31
This skill is purely educational documentation about property-based testing in Rust. All 36 static findings are false positives: the 'Ruby backtick execution' detections are markdown code fences, the 'weak cryptographic algorithm' matches are proptest framework references, and 'system reconnaissance' flags are email regex patterns in test examples. The skill is restricted to Read and Grep tools only.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.