Audit History
detection-sigma - 10 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v10 Latest | Jul 23, 2026, 05:41 AM | 2 confirmed | 1 | No capability change |
| v9 | Jul 7, 2026, 08:42 PM | 1 confirmed | 0 | No capability change |
| v8 | Jul 5, 2026, 02:24 AM | 1 confirmed | 1 | No capability change |
| v7 | Jul 5, 2026, 02:24 AM | 1 confirmed | 1 | No capability change |
| v6 | Jun 28, 2026, 05:30 AM | 1 confirmed | 0 | No capability change |
| v5 | Jan 16, 2026, 03:39 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 03:39 PM | No confirmed findings | 0 | Network accessExternal commands |
| v3 | Jan 10, 2026, 10:31 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 10:31 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 10:31 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 05:41 AM
Most static findings are false positives from defensive selectors, ATT&CK labels, citations, Markdown fences, and SIEM query examples. One network finding is confirmed because the deployment example performs an authenticated request. Separate findings cover disabled TLS verification, administrator placeholders, and unpinned dependencies.
Confirmed security concerns (2)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (21)
⚙️ External commands (50)
Jul 7, 2026, 08:42 PM
Most static findings are false positives caused by Sigma rule examples, MITRE ATT&CK references, public documentation links, and SIEM query snippets. I found one contextual issue: a deployment example uses placeholder administrator credentials and disables TLS verification, which should be revised before publication. No prompt injection or malicious execution instructions were found in the reviewed files.
Confirmed security concerns (1)
Risk Factors
🌐 Network access (21)
⚙️ External commands (131)
Jul 5, 2026, 02:24 AM
Most static hits are false positives caused by Sigma detection examples, ATT&CK labels, markdown command snippets, and reference links. One real documentation risk remains in the Splunk deployment example because it pairs placeholder credentials with disabled TLS verification. No prompt injection or malicious data-exfiltration intent was found in the reviewed skill files.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (11)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (21)
⚙️ External commands (131)
Jul 5, 2026, 02:24 AM
Most static hits are false positives caused by Sigma detection examples, ATT&CK labels, markdown command snippets, and reference links. One real documentation risk remains in the Splunk deployment example because it pairs placeholder credentials with disabled TLS verification. No prompt injection or malicious data-exfiltration intent was found in the reviewed skill files.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (11)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (21)
⚙️ External commands (131)
Jun 28, 2026, 05:30 AM
Static analysis reported many critical and high indicators, but most are false positives caused by Sigma detection examples, ATT&CK terminology, markdown command snippets, and reference URLs. One real documentation risk remains: a Splunk deployment example uses placeholder credentials and disables TLS verification. No confirmed malicious intent or prompt injection attempt was found, so publication is acceptable with a security warning.
Confirmed security concerns (1)
Static false positives ignored (4)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (38)
⚙️ External commands (474)
Detected Patterns
Jan 16, 2026, 03:39 PM
Documentation-only skill containing YAML templates and reference guides for defensive security detection engineering. All static findings are FALSE POSITIVES - the flagged patterns are detection rules designed to identify malicious activity, not perform it. This skill does not contain executable code, network access, or file system operations. Previous Claude audit correctly identified this as safe.
Risk Factors
🌐 Network access (38)
⚙️ External commands (474)
Jan 16, 2026, 03:39 PM
Documentation-only skill containing YAML templates and reference guides for defensive security detection engineering. All static findings are FALSE POSITIVES - the flagged patterns are detection rules designed to identify malicious activity, not perform it. This skill does not contain executable code, network access, or file system operations. Previous Claude audit correctly identified this as safe.
Risk Factors
🌐 Network access (38)
⚙️ External commands (474)
Jan 10, 2026, 10:31 AM
Documentation-only skill containing YAML templates and reference guides for defensive security detection engineering. No executable code, network access, or file system operations. All content describes legitimate defensive security patterns for threat detection and compliance monitoring.
Jan 10, 2026, 10:31 AM
Documentation-only skill containing YAML templates and reference guides for defensive security detection engineering. No executable code, network access, or file system operations. All content describes legitimate defensive security patterns for threat detection and compliance monitoring.
Jan 10, 2026, 10:31 AM
Documentation-only skill containing YAML templates and reference guides for defensive security detection engineering. No executable code, network access, or file system operations. All content describes legitimate defensive security patterns for threat detection and compliance monitoring.