Skills credits-handler Audit History
📦

Audit History

credits-handler - 8 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v8 LatestJul 6, 2026, 12:38 AM No confirmed findings0No capability change
v7 Jul 6, 2026, 12:38 AM No confirmed findings0External commands
v6 Jun 28, 2026, 03:54 AM No confirmed findings0 External commands
v5 Jan 16, 2026, 02:14 PM No confirmed findings0No capability change
v4 Jan 16, 2026, 02:14 PM No confirmed findings0External commands
v3 Jan 10, 2026, 09:52 AM No confirmed findings0No capability change
v2 Jan 10, 2026, 09:52 AM No confirmed findings0No capability change
v1 Jan 10, 2026, 09:52 AM No confirmed findings0Baseline

Jul 6, 2026, 12:38 AM

All static findings are false positives caused by Markdown inline code, code fences, and TypeScript or TSX examples. The scanned files show documentation for credit-system integration, with no shell execution, prompt injection, or data exfiltration intent.

2
Files scanned
217
Lines analyzed
1
Review items
0
False positives ignored
Audited by: codex

Jul 6, 2026, 12:38 AM

All static findings are false positives caused by Markdown inline code, code fences, and TypeScript or TSX examples. The scanned files show documentation for credit-system integration, with no shell execution, prompt injection, or data exfiltration intent.

2
Files scanned
217
Lines analyzed
1
Review items
0
False positives ignored
Audited by: codex

Jun 28, 2026, 03:54 AM

Static analysis reported many shell execution patterns and two weak cryptography patterns. Manual review found these are false positives from Markdown code spans, fenced TypeScript examples, file path references, and substring matches in prose; no executable shell, cryptography, network, filesystem, or prompt injection behavior was found.

2
Files scanned
217
Lines analyzed
0
Review items
2
False positives ignored
Static false positives ignored (2)

These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.

Low
Static Analyzer False Positive: Markdown Code References
The external command findings are inline Markdown code spans and fenced TypeScript or TSX examples that document app files, hooks, imports, and helper names. They are not Ruby backtick execution and do not execute commands from this skill.
The flagged text is visibly documentation and example application code inside Markdown. I found no executable script file, shell command, or instruction to run untrusted commands.
Low
Static Analyzer False Positive: Weak Cryptography Substring
The weak cryptography findings point to the YAML description and introductory prose, not to cryptographic APIs or algorithms. No hashing, encryption, or DES-like implementation is present in the reviewed files.
The cited lines describe the skill and contain no cryptographic operation. The scanner appears to have matched text substrings rather than code semantics.
No confirmed security findings were recorded for this completed audit.
Audited by: codex

Jan 10, 2026, 09:52 AM

This skill contains only documentation files (SKILL.md and reference.md). There is no executable code, scripts, network operations, or file system access. The skill provides guidance for implementing a credit system using TypeScript patterns and React hooks.

2
Files scanned
217
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 10, 2026, 09:52 AM

This skill contains only documentation files (SKILL.md and reference.md). There is no executable code, scripts, network operations, or file system access. The skill provides guidance for implementing a credit system using TypeScript patterns and React hooks.

2
Files scanned
217
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 10, 2026, 09:52 AM

This skill contains only documentation files (SKILL.md and reference.md). There is no executable code, scripts, network operations, or file system access. The skill provides guidance for implementing a credit system using TypeScript patterns and React hooks.

2
Files scanned
217
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude