Audit History
portfolio-context - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 20, 2026, 05:17 PM | No confirmed findings | 0 | External commands |
| v4 | Jun 27, 2026, 04:45 PM | No confirmed findings | 0 | External commands |
| v3 | Jan 16, 2026, 12:14 PM | No confirmed findings | 0 | No capability change |
| v2 | Jan 16, 2026, 12:14 PM | No confirmed findings | 0 | External commands |
| v1 | Jan 10, 2026, 09:12 AM | No confirmed findings | 0 | Baseline |
Jul 20, 2026, 05:17 PM
All six static findings are false positives caused by Markdown inline and fenced code formatting. The skill contains project documentation only and no executable commands, network instructions, credential handling, or prompt-injection content.
Risk Factors
⚙️ External commands (6)
Jun 27, 2026, 04:45 PM
Static analysis reported external command and weak cryptography patterns, but review found only Markdown inline code, a directory tree, and descriptive portfolio terminology. No executable code, shell invocation, cryptographic implementation, network access, filesystem access, secret handling, or prompt injection attempt was found in SKILL.md.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Jan 16, 2026, 12:14 PM
This skill is a pure documentation/context file containing no executable code. All 22 static findings are FALSE POSITIVES caused by the analyzer misinterpreting JSON metadata fields, markdown code fences, and documentation text as security threats. No network calls, file access, or command execution capabilities exist.
Risk Factors
⚙️ External commands (6)
Jan 16, 2026, 12:14 PM
This skill is a pure documentation/context file containing no executable code. All 22 static findings are FALSE POSITIVES caused by the analyzer misinterpreting JSON metadata fields, markdown code fences, and documentation text as security threats. No network calls, file access, or command execution capabilities exist.
Risk Factors
⚙️ External commands (6)
Jan 10, 2026, 09:12 AM
Pure markdown context file with no executable code. Contains project documentation only. No file access, network calls, or command execution capabilities. Safe for publication.