Audit History
content-gap-analysis - 4 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v4 Latest | Jul 12, 2026, 11:31 AM | No confirmed findings | 1 | No capability change |
| v3 | Jul 12, 2026, 11:31 AM | No confirmed findings | 1 | No capability change |
| v2 | Jul 6, 2026, 04:06 PM | 1 confirmed | 2 | No capability change |
| v1 | Jul 4, 2026, 03:53 PM | No confirmed findings | 0 | Baseline |
Jul 12, 2026, 11:31 AM
Most static alerts are false positives caused by Markdown fences, metadata URLs, relative documentation links, and ordinary scoring language. The command at SKILL.md:50 is a genuine medium-risk external command because a user-derived domain placeholder is passed without explicit validation or shell-safe argument handling.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (16)
🌐 Network access (2)
📁 Filesystem access (8)
Jul 12, 2026, 11:31 AM
Most static alerts are false positives caused by Markdown fences, metadata URLs, relative documentation links, and ordinary scoring language. The command at SKILL.md:50 is a genuine medium-risk external command because a user-derived domain placeholder is passed without explicit validation or shell-safe argument handling.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (16)
🌐 Network access (2)
📁 Filesystem access (8)
Jul 6, 2026, 04:06 PM
Most static findings are false positives from Markdown code fences, fixed memory paths, metadata URLs, and documentation links. The confirmed risk is the optional connector workflow, which asks agents to run local scripts and perform outbound competitor scraping.
Confirmed security concerns (1)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (16)
🌐 Network access (2)
📁 Filesystem access (8)
Jul 4, 2026, 03:53 PM
All static findings are false positives after contextual review. The flagged items are Markdown prompt fences, repository documentation links, homepage metadata, bounded workspace paths, or optional connector instructions; no prompt injection, credential exfiltration, arbitrary command execution, or malicious traversal intent was found.