Audit History
API JWT Authenticator - 10 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v10 Latest | Jul 18, 2026, 09:32 AM | No confirmed findings | 0 | No capability change |
| v9 | Jul 17, 2026, 10:29 PM | 1 confirmed | 0 | No capability change |
| v8 | Jul 7, 2026, 06:12 PM | No confirmed findings | 0 | No capability change |
| v7 | Jul 6, 2026, 01:19 AM | No confirmed findings | 0 | External commands |
| v6 | Jun 28, 2026, 03:48 AM | No confirmed findings | 0 | External commands |
| v5 | Jan 16, 2026, 03:39 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 03:39 PM | No confirmed findings | 0 | External commands |
| v3 | Jan 10, 2026, 09:48 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 09:48 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 09:48 AM | No confirmed findings | 0 | Baseline |
Jul 18, 2026, 09:32 AM
All nine static detections are false positives. Markdown inline-code delimiters around JWT terms were misidentified as shell backticks, and the remaining detections describe defensive authentication behavior rather than reconnaissance. No prompt injection, exfiltration intent, or executable commands were found in SKILL.md.
Risk Factors
⚙️ External commands (5)
Jul 17, 2026, 10:29 PM
All nine static findings are false positives caused by Markdown text, inline code formatting, or ordinary security terminology. The skill contains no executable commands, but its JWT validation guidance omits explicit algorithm allowlisting.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (5)
Jul 7, 2026, 06:12 PM
All nine static findings are false positives caused by markdown formatting and authentication terminology in SKILL.md. The skill is conceptual guidance for JWT authentication in FastAPI and does not contain executable code, network calls, prompt injection text, or data exfiltration instructions.
Risk Factors
⚙️ External commands (5)
Jul 6, 2026, 01:19 AM
The static findings are false positives caused by Markdown inline code and authentication terminology in SKILL.md. I found no evidence of command execution, system reconnaissance, prompt injection, or malicious intent in the reviewed skill file.
Risk Factors
⚙️ External commands (5)
Jun 28, 2026, 03:48 AM
Static analysis flagged Markdown backticks, JWT terminology, and HTTP authentication documentation as suspicious patterns. Review found no executable code, shell invocation, prompt injection, malware behavior, or data exfiltration in SKILL.md. The skill is a conceptual security guide and is safe to publish with low residual risk.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Jan 16, 2026, 03:39 PM
This is a pure documentation skill providing conceptual guidance for implementing JWT authentication in FastAPI APIs. Contains no executable code, no network calls, no filesystem operations, and no external command execution. The static analysis findings are false positives triggered by security-related terminology in documentation (JWT, authorization, tokens, roles) and metadata fields. All 27 static findings are dismissed as keyword-pattern false positives.
Risk Factors
⚙️ External commands (6)
Jan 16, 2026, 03:39 PM
This is a pure documentation skill providing conceptual guidance for implementing JWT authentication in FastAPI APIs. Contains no executable code, no network calls, no filesystem operations, and no external command execution. The static analysis findings are false positives triggered by security-related terminology in documentation (JWT, authorization, tokens, roles) and metadata fields. All 27 static findings are dismissed as keyword-pattern false positives.
Risk Factors
⚙️ External commands (6)
Jan 10, 2026, 09:48 AM
Pure documentation-based conceptual skill containing only a SKILL.md file. No executable code, no network calls, no filesystem access beyond its own file. The content provides guidance on implementing JWT authentication following security best practices.
Jan 10, 2026, 09:48 AM
Pure documentation-based conceptual skill containing only a SKILL.md file. No executable code, no network calls, no filesystem access beyond its own file. The content provides guidance on implementing JWT authentication following security best practices.
Jan 10, 2026, 09:48 AM
Pure documentation-based conceptual skill containing only a SKILL.md file. No executable code, no network calls, no filesystem access beyond its own file. The content provides guidance on implementing JWT authentication following security best practices.