Audit History
preference-frequency-manager - 6 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v6 Latest | Jul 27, 2026, 11:39 AM | No confirmed findings | 0 | No capability change |
| v5 | Jul 13, 2026, 02:32 PM | No confirmed findings | 1 | No capability change |
| v4 | Jul 13, 2026, 02:32 PM | No confirmed findings | 1 | No capability change |
| v3 | Jul 12, 2026, 01:35 PM | No confirmed findings | 0 | No capability change |
| v2 | Jul 6, 2026, 06:37 PM | No confirmed findings | 0 | No capability change |
| v1 | Jul 4, 2026, 04:25 PM | No confirmed findings | 0 | Baseline |
Jul 27, 2026, 11:39 AM
All 37 static detections are false positives caused by Markdown code formatting, relative documentation links, fixed memory paths, and homepage metadata. The skill contains instructional content only and explicitly tells agents to treat imported data as untrusted. No prompt injection, command execution, network exfiltration, environment access, or unsafe filesystem behavior was found.
Risk Factors
βοΈ External commands (13)
π Network access (2)
π Filesystem access (21)
π Env variables (1)
Jul 13, 2026, 02:32 PM
Contextual review dismissed 36 static alerts caused by Markdown fences, inline code, metadata URLs, and fixed repository links. The user-derived output filename lacks an explicit sanitization rule, so a crafted name could escape the intended memory directory.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (13)
π Network access (2)
π Filesystem access (21)
π Env variables (1)
Jul 13, 2026, 02:32 PM
Contextual review dismissed 36 static alerts caused by Markdown fences, inline code, metadata URLs, and fixed repository links. The user-derived output filename lacks an explicit sanitization rule, so a crafted name could escape the intended memory directory.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (13)
π Network access (2)
π Filesystem access (21)
π Env variables (1)
Jul 12, 2026, 01:35 PM
All 37 static findings are false positives caused by Markdown fences, inline formatting, public homepage metadata, and fixed repository-relative links. The skill contains no executable commands, network requests, environment access, path traversal logic, or prompt injection.
Risk Factors
βοΈ External commands (13)
π Network access (2)
π Filesystem access (21)
π Env variables (1)
Jul 6, 2026, 06:37 PM
All static findings are false positives after context review. The file contains Markdown examples, metadata, relative documentation links, and user-confirmed memory output guidance, with no executable code, network calls, environment reads, or path traversal instructions.
Risk Factors
βοΈ External commands (12)
π Network access (2)
π Filesystem access (22)
π Env variables (1)
Jul 4, 2026, 04:25 PM
All static findings were adjudicated as false positives. The command items are Markdown fences or inline formatting, the network items are homepage metadata, and the filesystem items are fixed repository links or a local memory path template. No prompt injection, exfiltration intent, or business-logic abuse was found in SKILL.md.