Audit History
entity-optimizer - 6 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v6 Latest | Jul 12, 2026, 12:20 PM | No confirmed findings | 0 | No capability change |
| v5 | Jul 12, 2026, 12:20 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 7, 2026, 06:19 AM | 2 confirmed | 2 | No capability change |
| v3 | Jul 6, 2026, 05:09 PM | No confirmed findings | 2 | No capability change |
| v2 | Jul 6, 2026, 05:09 PM | No confirmed findings | 2 | No capability change |
| v1 | Jul 4, 2026, 04:03 PM | No confirmed findings | 0 | Baseline |
Jul 12, 2026, 12:20 PM
All 36 static findings are false positives caused by Markdown formatting, documentation links, metadata URLs, or bounded commands with fixed executables and quoted arguments. No prompt injection, credential exposure, unsafe dynamic execution, or malicious data-handling intent was found.
Risk Factors
📁 Filesystem access (14)
⚙️ External commands (16)
🌐 Network access (2)
Jul 12, 2026, 12:20 PM
All 36 static findings are false positives caused by Markdown formatting, documentation links, metadata URLs, or bounded commands with fixed executables and quoted arguments. No prompt injection, credential exposure, unsafe dynamic execution, or malicious data-handling intent was found.
Risk Factors
📁 Filesystem access (14)
⚙️ External commands (16)
🌐 Network access (2)
Jul 7, 2026, 06:19 AM
Most static alerts are false positives caused by Markdown links, code fences, metadata URLs, and inline documentation. Two external command findings are confirmed because the skill instructs running local connector scripts with user-provided entity inputs. Additional review found a medium filename-boundary risk for saved entity profiles and a low privacy risk from external entity lookups.
Confirmed security concerns (2)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
📁 Filesystem access (11)
⚙️ External commands (26)
🌐 Network access (2)
Jul 6, 2026, 05:09 PM
Most static findings are false positives caused by markdown code fences, inline code, relative documentation links, and schema terminology. Two findings are confirmed because the skill recommends local Python connector helpers that run with user-derived values. No prompt injection, credential access, or data exfiltration intent was found in the reviewed files.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
📁 Filesystem access (11)
⚙️ External commands (26)
🌐 Network access (2)
Jul 6, 2026, 05:09 PM
Most static findings are false positives caused by markdown code fences, inline code, relative documentation links, and schema terminology. Two findings are confirmed because the skill recommends local Python connector helpers that run with user-derived values. No prompt injection, credential access, or data exfiltration intent was found in the reviewed files.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
📁 Filesystem access (11)
⚙️ External commands (26)
🌐 Network access (2)
Jul 4, 2026, 04:03 PM
No malicious intent, prompt injection, data exfiltration, or unauthorized execution was found. The static findings are false positives from Markdown links, code fences, inline path formatting, homepage metadata, and optional documented local helper commands. The skill includes consent and privacy checks before storing person entity profiles.