Audit History
writing-types - 4 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v4 Latest | 6 июл. 2026 г., 15:08 | No confirmed findings | 0 | No capability change |
| v3 | 6 июл. 2026 г., 15:08 | No confirmed findings | 0 | External commands |
| v2 | 30 июн. 2026 г., 00:50 | No confirmed findings | 0 | No capability change |
| v1 | 23 янв. 2026 г., 02:42 | No confirmed findings | 0 | Baseline |
6 июл. 2026 г., 15:08
Both static external command findings are false positives caused by Markdown inline code around the srs/types path. SKILL.md contains only prose instructions for organizing TypeScript types and interfaces, with no executable code or command instructions. No evidence found of prompt injection, data exfiltration, or other semantic abuse.
Risk Factors
⚙️ External commands (2)
6 июл. 2026 г., 15:08
Both static external command findings are false positives caused by Markdown inline code around the srs/types path. SKILL.md contains only prose instructions for organizing TypeScript types and interfaces, with no executable code or command instructions. No evidence found of prompt injection, data exfiltration, or other semantic abuse.
Risk Factors
⚙️ External commands (2)
30 июн. 2026 г., 00:50
Static analysis flagged backtick usage and a weak cryptography pattern in `SKILL.md`, but review found only Markdown prose around the `srs/types` path. No shell execution, cryptographic code, data exfiltration, prompt injection, or other semantic threat was found.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
23 янв. 2026 г., 02:42
All static findings are false positives. The SKILL.md file contains only markdown documentation with inline code formatting. Backticks are used for path references, not shell execution. No cryptographic algorithms, network calls, or dangerous code patterns present.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.