Audit History
content-reviewer - 4 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v4 Latest | Jul 12, 2026, 11:39 AM | No confirmed findings | 0 | No capability change |
| v3 | Jul 12, 2026, 11:39 AM | No confirmed findings | 0 | No capability change |
| v2 | Jul 6, 2026, 04:16 PM | 1 confirmed | 1 | No capability change |
| v1 | Jul 4, 2026, 03:50 PM | No confirmed findings | 1 | Baseline |
Jul 12, 2026, 11:39 AM
All 44 static findings are false positives caused by Markdown links, inline code formatting, fixed local commands, metadata URLs, or ordinary review language. No prompt injection, arbitrary path handling, command injection, unauthorized network activity, or malicious intent was found.
Risk Factors
π Filesystem access (20)
βοΈ External commands (18)
π Network access (2)
Jul 12, 2026, 11:39 AM
All 44 static findings are false positives caused by Markdown links, inline code formatting, fixed local commands, metadata URLs, or ordinary review language. No prompt injection, arbitrary path handling, command injection, unauthorized network activity, or malicious intent was found.
Risk Factors
π Filesystem access (20)
βοΈ External commands (18)
π Network access (2)
Jul 6, 2026, 04:16 PM
Most static filesystem and command-execution alerts are Markdown links, code spans, or workflow labels rather than executable behavior. One risk remains: the standalone fallback trusts mutable raw GitHub files from the main branch. No prompt injection attempt was found in the reviewed files.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (31)
βοΈ External commands (18)
π Network access (3)
Jul 4, 2026, 03:50 PM
The audit found no prompt-injection attempt, executable command path, or malicious filesystem traversal in the reviewed Markdown files. Most static findings are false positives from fixed documentation links, inline code formatting, template fences, connector placeholders, or platform labels. One low-risk network issue remains: the standalone fallback can fetch mutable reference content from GitHub at runtime.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.