Audit History
performance-monitor - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 12, 2026, 01:27 PM | No confirmed findings | 1 | No capability change |
| v6 | Jul 12, 2026, 01:27 PM | No confirmed findings | 1 | No capability change |
| v5 | Jul 10, 2026, 11:39 AM | 1 confirmed | 1 | No capability change |
| v4 | Jul 9, 2026, 12:19 PM | No confirmed findings | 1 | No capability change |
| v3 | Jul 6, 2026, 06:28 PM | No confirmed findings | 1 | No capability change |
| v2 | Jul 6, 2026, 06:28 PM | No confirmed findings | 1 | No capability change |
| v1 | Jul 4, 2026, 04:12 PM | No confirmed findings | 0 | Baseline |
Jul 12, 2026, 01:27 PM
Most detections are Markdown syntax, documentation links, or metadata URLs without executable behavior. SKILL.md line 63 directs agents to run a Python ledger command with a domain argument. This creates command execution and input-handling risk, but no malicious or exfiltration intent was found.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (18)
🌐 Network access (2)
📁 Filesystem access (10)
🔑 Env variables (1)
Jul 12, 2026, 01:27 PM
Most detections are Markdown syntax, documentation links, or metadata URLs without executable behavior. SKILL.md line 63 directs agents to run a Python ledger command with a domain argument. This creates command execution and input-handling risk, but no malicious or exfiltration intent was found.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (18)
🌐 Network access (2)
📁 Filesystem access (10)
🔑 Env variables (1)
Jul 10, 2026, 11:39 AM
Most static alerts are false positives caused by Markdown formatting, relative documentation links, KPI terminology, and metadata URLs. The skill does direct the host to run a Python ledger command, and its unquoted domain placeholder creates a potential command-injection path. No prompt injection, credential exfiltration, or malicious traversal intent was found.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (18)
🌐 Network access (2)
📁 Filesystem access (10)
🔑 Env variables (1)
Jul 9, 2026, 12:19 PM
Most static findings are Markdown formatting, fixed relative documentation links, or SEO report terms misclassified as security issues. One finding is confirmed: the measurement loop suggests running a local Python connector with user-provided metric values, which requires permission and argument handling.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (18)
🌐 Network access (2)
📁 Filesystem access (10)
🔑 Env variables (1)
Jul 6, 2026, 06:28 PM
Most static findings are false positives from Markdown code spans, fixed repository links, and SEO terminology such as indexation and schema. One confirmed risk remains: the measurement loop instructs the agent to run a local Python ledger command from CLAUDE_PLUGIN_ROOT. No evidence of prompt injection, credential exfiltration, or malicious intent was found in the reviewed files.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (18)
🌐 Network access (2)
📁 Filesystem access (10)
🔑 Env variables (1)
Jul 6, 2026, 06:28 PM
Most static findings are false positives from Markdown code spans, fixed repository links, and SEO terminology such as indexation and schema. One confirmed risk remains: the measurement loop instructs the agent to run a local Python ledger command from CLAUDE_PLUGIN_ROOT. No evidence of prompt injection, credential exfiltration, or malicious intent was found in the reviewed files.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (18)
🌐 Network access (2)
📁 Filesystem access (10)
🔑 Env variables (1)
Jul 4, 2026, 04:12 PM
The static alerts are false positives caused by Markdown inline code, fenced prompt examples, relative repository links, static homepage URLs, and one fixed local ledger command example. I found no evidence of prompt injection, credential access, data exfiltration, malicious network behavior, or unsafe path traversal in the reviewed files.