Audit History
Backend (FastAPI) - 10 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v10 Latest | Jul 18, 2026, 09:39 AM | No confirmed findings | 0 | No capability change |
| v9 | Jul 17, 2026, 11:37 PM | No confirmed findings | 0 | No capability change |
| v8 | Jul 7, 2026, 06:57 PM | No confirmed findings | 0 | No capability change |
| v7 | Jul 6, 2026, 01:36 AM | No confirmed findings | 0 | No capability change |
| v6 | Jun 28, 2026, 04:21 AM | No confirmed findings | 0 | No capability change |
| v5 | Jan 16, 2026, 04:11 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 04:11 PM | No confirmed findings | 0 | Env variablesExternal commands |
| v3 | Jan 10, 2026, 09:48 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 09:48 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 09:48 AM | No confirmed findings | 0 | Baseline |
Jul 18, 2026, 09:39 AM
All 18 static findings are false positives. The scanner interpreted Markdown inline-code delimiters as shell backticks and documented environment-variable names as environment access. SKILL.md is a concise architecture reference and contains no executable code, credential values, or prompt-injection content.
Risk Factors
⚙️ External commands (16)
🔑 Env variables (2)
Jul 17, 2026, 11:37 PM
All 18 static findings are false positives caused by Markdown code formatting and documented configuration names. SKILL.md contains no executable scripts, environment access, credential values, prompt injection, or unsafe operational instructions.
Risk Factors
⚙️ External commands (16)
🔑 Env variables (2)
Jul 7, 2026, 06:57 PM
The external-command findings are false positives caused by Markdown inline code and one static local run command in SKILL.md. The environment findings only name required variables and do not expose, read, or transmit secrets. No prompt injection or data-exfiltration intent was found.
Risk Factors
⚙️ External commands (16)
🔑 Env variables (2)
Jul 6, 2026, 01:36 AM
All static external command findings are markdown inline code spans that document paths, endpoints, and fixed development commands. The secret-key findings only list environment variable names, with no evidence of secret value access or exfiltration. No prompt injection or malicious intent was found in SKILL.md.
Risk Factors
⚙️ External commands (16)
🔑 Env variables (2)
Jun 28, 2026, 04:21 AM
Static analysis flagged Markdown backticks, environment variable names, and one weak-cryptography pattern. Review found documentation text only: local run examples, endpoint names, file names, and required secret variable names, with no executable code, secret reading, network exfiltration, or prompt injection. The skill is safe to publish with low residual risk from documented operational commands and secret configuration names.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (16)
🔑 Env variables (2)
Jan 16, 2026, 04:11 PM
Documentation-only skill containing no executable code. The SKILL.md file describes FastAPI backend architecture without any scripts, network calls, or file system access capabilities. All 40 static findings are false positives caused by the scanner misinterpreting documentation text as code patterns.
Risk Factors
🔑 Env variables (2)
Jan 16, 2026, 04:11 PM
Documentation-only skill containing no executable code. The SKILL.md file describes FastAPI backend architecture without any scripts, network calls, or file system access capabilities. All 40 static findings are false positives caused by the scanner misinterpreting documentation text as code patterns.
Risk Factors
🔑 Env variables (2)
Jan 10, 2026, 09:48 AM
Documentation-only skill containing no executable code. The SKILL.md file describes FastAPI backend architecture without any scripts, network calls, or file system access capabilities.
Jan 10, 2026, 09:48 AM
Documentation-only skill containing no executable code. The SKILL.md file describes FastAPI backend architecture without any scripts, network calls, or file system access capabilities.
Jan 10, 2026, 09:48 AM
Documentation-only skill containing no executable code. The SKILL.md file describes FastAPI backend architecture without any scripts, network calls, or file system access capabilities.