Audit History
performance-analyzer - 11 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v11 Latest | Jul 12, 2026, 01:24 PM | 1 confirmed | 2 | No capability change |
| v10 | Jul 12, 2026, 01:24 PM | 1 confirmed | 2 | No capability change |
| v9 | Jul 9, 2026, 07:24 AM | No confirmed findings | 1 | No capability change |
| v8 | Jul 9, 2026, 12:20 PM | No confirmed findings | 2 | No capability change |
| v7 | Jul 9, 2026, 07:24 AM | No confirmed findings | 1 | No capability change |
| v6 | Jul 9, 2026, 03:55 AM | No confirmed findings | 2 | No capability change |
| v5 | Jul 9, 2026, 01:04 AM | No confirmed findings | 2 | No capability change |
| v4 | Jul 7, 2026, 06:33 AM | No confirmed findings | 2 | No capability change |
| v3 | Jul 6, 2026, 06:23 PM | No confirmed findings | 2 | No capability change |
| v2 | Jul 6, 2026, 06:23 PM | No confirmed findings | 2 | No capability change |
| v1 | Jul 4, 2026, 04:16 PM | No confirmed findings | 0 | Baseline |
Jul 12, 2026, 01:24 PM
Most alerts are false positives caused by Markdown links, code fences, placeholders, and metadata URLs. However, SKILL.md line 58 directs execution of an out-of-package Python connector and use of environment-held API credentials. Publication should require connector review, explicit network consent, and documented credential handling.
Confirmed security concerns (1)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (21)
βοΈ External commands (17)
π Network access (2)
π Env variables (1)
Jul 12, 2026, 01:24 PM
Most alerts are false positives caused by Markdown links, code fences, placeholders, and metadata URLs. However, SKILL.md line 58 directs execution of an out-of-package Python connector and use of environment-held API credentials. Publication should require connector review, explicit network consent, and documented credential handling.
Confirmed security concerns (1)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (21)
βοΈ External commands (17)
π Network access (2)
π Env variables (1)
Jul 9, 2026, 07:24 AM
Most findings are false positives caused by Markdown links, code fences, placeholders, and homepage metadata. One medium issue remains: the skill instructs the agent to run an optional Python YouTube connector from CLAUDE_PLUGIN_ROOT, which is legitimate but still external command execution. No prompt injection, data-exfiltration intent, or malicious override text was found in the reviewed files.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (21)
βοΈ External commands (15)
π Network access (2)
π Env variables (1)
Jul 9, 2026, 12:20 PM
Most static findings are false positives caused by Markdown links, code fences, placeholder notation, and fixed memory paths. The confirmed risks are the optional YouTube connector command and its use of YOUTUBE_API_KEY. No prompt injection or malicious data-exfiltration intent was found.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (21)
βοΈ External commands (15)
π Network access (2)
π Env variables (1)
Jul 9, 2026, 07:24 AM
Most findings are false positives caused by Markdown links, code fences, placeholders, and homepage metadata. One medium issue remains: the skill instructs the agent to run an optional Python YouTube connector from CLAUDE_PLUGIN_ROOT, which is legitimate but still external command execution. No prompt injection, data-exfiltration intent, or malicious override text was found in the reviewed files.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (21)
βοΈ External commands (15)
π Network access (2)
π Env variables (1)
Jul 9, 2026, 03:55 AM
The static analyzer produced many high-severity path traversal and command-pattern hits, but most are Markdown links, templates, metadata, or placeholder labels. The retained risks are the documented YouTube connector command and its API-key dependency, which are legitimate but require installer visibility because they execute local code and read a secret-bearing environment variable.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (21)
βοΈ External commands (15)
π Network access (2)
π Env variables (1)
Jul 9, 2026, 01:04 AM
Most static findings are false positives caused by Markdown links, code fences, placeholders, and influencer handle examples. One documented connector command is a real external-command risk, and its use of YOUTUBE_API_KEY is a real environment-access risk, but I found no malicious intent or prompt injection.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (21)
βοΈ External commands (15)
π Network access (2)
π Env variables (1)
Jul 7, 2026, 06:33 AM
Most static alerts are false positives from Markdown links, fenced examples, placeholders, and sample creator handles. The confirmed issue is SKILL.md line 58, which instructs agents to run a local YouTube connector and use YOUTUBE_API_KEY. No prompt injection or covert exfiltration intent was found in the reviewed files.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (21)
βοΈ External commands (15)
π Network access (2)
π Env variables (1)
Jul 6, 2026, 06:23 PM
Most static findings are false positives from Markdown links, fenced examples, inline path labels, and homepage metadata. The confirmed risks are limited to a YouTube connector command that runs local Python and may read YOUTUBE_API_KEY; no prompt injection or exfiltration intent was found.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (21)
βοΈ External commands (15)
π Network access (2)
π Env variables (1)
Jul 6, 2026, 06:23 PM
Most static findings are false positives from Markdown links, fenced examples, inline path labels, and homepage metadata. The confirmed risks are limited to a YouTube connector command that runs local Python and may read YOUTUBE_API_KEY; no prompt injection or exfiltration intent was found.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (21)
βοΈ External commands (15)
π Network access (2)
π Env variables (1)
Jul 4, 2026, 04:16 PM
All static findings were reviewed against the cited lines and are false positives. The high filesystem findings are relative Markdown links or workspace memory conventions, the command findings are Markdown examples or bounded connector documentation, and no prompt injection or data-exfiltration intent was found.