Audit History
roi-calculator - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 12, 2026, 01:51 PM | No confirmed findings | 3 | No capability change |
| v4 | Jul 12, 2026, 01:51 PM | No confirmed findings | 3 | No capability change |
| v3 | Jul 7, 2026, 06:41 AM | No confirmed findings | 0 | No capability change |
| v2 | Jul 6, 2026, 06:58 PM | No confirmed findings | 0 | No capability change |
| v1 | Jul 4, 2026, 04:24 PM | No confirmed findings | 0 | Baseline |
Jul 12, 2026, 01:51 PM
Most static findings are false positives caused by Markdown links, code fences, placeholders, and ordinary marketing terms. Three findings confirm one underlying behavior: the skill uses shell substitution and invokes a repository-local Python scoring script.
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (22)
π Filesystem access (21)
π Network access (2)
Jul 12, 2026, 01:51 PM
Most static findings are false positives caused by Markdown links, code fences, placeholders, and ordinary marketing terms. Three findings confirm one underlying behavior: the skill uses shell substitution and invokes a repository-local Python scoring script.
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (22)
π Filesystem access (21)
π Network access (2)
Jul 7, 2026, 06:41 AM
Reviewed 42 static findings across SKILL.md and references/roi-templates.md. The detections are false positives from markdown links, examples, inline labels, placeholders, and homepage metadata; no command execution, network call, prompt injection, or malicious file access intent was found.
Risk Factors
π Filesystem access (18)
βοΈ External commands (16)
π Network access (2)
Jul 6, 2026, 06:58 PM
All static findings were reviewed against SKILL.md and references/roi-templates.md. I found no prompt injection, command execution, data exfiltration, or malicious network behavior; the alerts are false positives from Markdown links, code fences, placeholders, and GitHub metadata.
Risk Factors
π Filesystem access (18)
βοΈ External commands (16)
π Network access (2)
Jul 4, 2026, 04:24 PM
Static analysis flagged Markdown links, code fences, placeholders, and homepage metadata as risky patterns. The cited context shows documentation-only ROI templates with no command execution, network calls, prompt injection, or malicious file access.