Audit History
prd-to-appspec - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 6, 2026, 02:32 PM | No confirmed findings | 0 | No capability change |
| v8 | Jul 6, 2026, 02:32 PM | No confirmed findings | 0 | No capability change |
| v7 | Jul 6, 2026, 01:45 AM | No confirmed findings | 0 | Network accessExternal commands |
| v6 | Jun 27, 2026, 06:55 PM | No confirmed findings | 1 | Network accessExternal commands |
| v5 | Jan 16, 2026, 01:42 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 01:42 PM | No confirmed findings | 0 | Network accessFilesystem accessExternal commands |
| v3 | Jan 10, 2026, 09:46 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 09:46 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 09:46 AM | No confirmed findings | 0 | Baseline |
Jul 6, 2026, 02:32 PM
The flagged network, filesystem, command, and reconnaissance patterns are documentation examples, Markdown links, code fences, or validation text. I found no semantic evidence of data exfiltration, prompt injection, or instructions to execute untrusted content.
Risk Factors
🌐 Network access (1)
📁 Filesystem access (2)
⚙️ External commands (5)
Jul 6, 2026, 02:32 PM
The flagged network, filesystem, command, and reconnaissance patterns are documentation examples, Markdown links, code fences, or validation text. I found no semantic evidence of data exfiltration, prompt injection, or instructions to execute untrusted content.
Risk Factors
🌐 Network access (1)
📁 Filesystem access (2)
⚙️ External commands (5)
Jul 6, 2026, 01:45 AM
The static network, path traversal, blocker, and external command matches are documentation examples rather than executable behavior. No prompt injection or malicious intent was found in the reviewed skill files.
Risk Factors
🌐 Network access (1)
📁 Filesystem access (2)
⚙️ External commands (5)
Jun 27, 2026, 06:55 PM
Static analysis reported many high-risk patterns, but manual review found they are Markdown examples, XML templates, inline code ticks, and prose references. No executable scripts, malicious network calls, credential access, prompt injection, or data exfiltration intent were found. The main residual risk is expected local filesystem access to read a user-provided PRD and write an app_spec.txt output.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
📁 Filesystem access (3)
Jan 16, 2026, 01:42 PM
Pure documentation skill containing only markdown files. All 151 static findings are false positives caused by the scanner misinterpreting Pydantic validators as crypto algorithms, markdown code fences as shell execution, and documentation links as path traversal. No executable code, scripts, network operations, or file system access capabilities.
Risk Factors
🌐 Network access (2)
📁 Filesystem access (4)
⚙️ External commands (105)
Jan 16, 2026, 01:42 PM
Pure documentation skill containing only markdown files. All 151 static findings are false positives caused by the scanner misinterpreting Pydantic validators as crypto algorithms, markdown code fences as shell execution, and documentation links as path traversal. No executable code, scripts, network operations, or file system access capabilities.
Risk Factors
🌐 Network access (2)
📁 Filesystem access (4)
⚙️ External commands (105)
Jan 10, 2026, 09:46 AM
Pure documentation skill containing only markdown files. No executable code, scripts, network operations, or file system access capabilities. All content is workflow guidance for transforming PRDs to XML specifications.
Jan 10, 2026, 09:46 AM
Pure documentation skill containing only markdown files. No executable code, scripts, network operations, or file system access capabilities. All content is workflow guidance for transforming PRDs to XML specifications.
Jan 10, 2026, 09:46 AM
Pure documentation skill containing only markdown files. No executable code, scripts, network operations, or file system access capabilities. All content is workflow guidance for transforming PRDs to XML specifications.