Audit History
Agent Development - 10 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v10 Latest | Jul 18, 2026, 10:00 AM | No confirmed findings | 0 | No capability change |
| v9 | Jul 18, 2026, 12:39 AM | No confirmed findings | 0 | No capability change |
| v8 | Jul 7, 2026, 07:24 PM | No confirmed findings | 0 | No capability change |
| v7 | Jul 6, 2026, 01:50 AM | No confirmed findings | 0 | No capability change |
| v6 | Jun 28, 2026, 06:03 AM | No confirmed findings | 0 | No capability change |
| v5 | Jan 16, 2026, 03:08 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 03:08 PM | No confirmed findings | 0 | External commands Contains scripts |
| v3 | Jan 9, 2026, 02:53 PM | No confirmed findings | 0 | No capability change |
| v2 | Jan 9, 2026, 02:53 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 9, 2026, 02:53 PM | No confirmed findings | 0 | Baseline |
Jul 18, 2026, 10:00 AM
All 82 static findings are false positives from Markdown backticks, instructional prose, or the local validator shell syntax. The validator parses a supplied file with quoted values and does not evaluate its contents. No prompt injection, data exfiltration, or malicious intent was found in the reviewed materials.
Risk Factors
📁 Filesystem access (2)
⚙️ External commands (50)
Jul 18, 2026, 12:39 AM
All static alerts were reviewed as false positives. The flagged markdown backticks, ellipses, and validation shell commands are documentation examples or fixed local parsing commands, not malicious behavior. No prompt injection attempt or data exfiltration intent was found.
Risk Factors
📁 Filesystem access (2)
⚙️ External commands (50)
Jul 7, 2026, 07:24 PM
All static alerts were reviewed as false positives. The flagged markdown backticks, ellipses, and validation shell commands are documentation examples or fixed local parsing commands, not malicious behavior. No prompt injection attempt or data exfiltration intent was found.
Risk Factors
📁 Filesystem access (2)
⚙️ External commands (69)
Jul 6, 2026, 01:50 AM
Static analysis primarily matched Markdown inline code, file:line examples, and ordinary shell parsing in a local validator. No prompt injection attempts, hidden network activity, credential exfiltration, destructive commands, or path traversal logic were found. The validation script should still be run only on files the user chooses.
Risk Factors
📁 Filesystem access (2)
⚙️ External commands (69)
Jun 28, 2026, 06:03 AM
Official Anthropic skill reviewed with minimal audit scope. Static analysis flagged external command and filesystem references, but they relate to documented examples and a local validation script rather than hidden execution. No prompt injection attempts or malicious behavior were identified.
Risk Factors
⚙️ External commands (227)
📁 Filesystem access (2)
Jan 16, 2026, 03:08 PM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
⚙️ External commands (227)
📁 Filesystem access (2)
Detected Patterns
Jan 16, 2026, 03:08 PM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
⚙️ External commands (227)
📁 Filesystem access (2)
Detected Patterns
Jan 9, 2026, 02:53 PM
Official Anthropic skill containing only documentation and a read-only validation script. No network, filesystem write, or external command execution risks. Safe for publishing.
Risk Factors
⚡ Contains scripts (1)
📁 Filesystem access (1)
Jan 9, 2026, 02:53 PM
Official Anthropic skill containing only documentation and a read-only validation script. No network, filesystem write, or external command execution risks. Safe for publishing.
Risk Factors
⚡ Contains scripts (1)
📁 Filesystem access (1)
Jan 9, 2026, 02:53 PM
Official Anthropic skill containing only documentation and a read-only validation script. No network, filesystem write, or external command execution risks. Safe for publishing.