Audit History
ir-velociraptor - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 23, 2026, 06:05 AM | 8 confirmed | 34 | No capability change |
| v8 | Jul 7, 2026, 08:59 PM | 5 confirmed | 32 | No capability change |
| v7 | Jul 6, 2026, 12:42 AM | 5 confirmed | 33 | No capability change |
| v6 | Jun 28, 2026, 05:41 AM | 7 confirmed | 0 | No capability change |
| v5 | Jan 16, 2026, 03:43 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 03:43 PM | No confirmed findings | 0 | Network accessExternal commandsFilesystem accessEnv variablesContains scripts |
| v3 | Jan 10, 2026, 10:42 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 10:42 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 10:42 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 06:05 AM
Most static alerts are documentation syntax, placeholders, or read-only defensive queries. Confirmed risks include remote script execution, privileged deployment, broad network exposure, and sensitive temporary files. CI bypasses and insecure deployment examples require correction before publication.
Confirmed security concerns (8)
Capability review items (34)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (50)
⚙️ External commands (50)
📁 Filesystem access (3)
🔑 Env variables (25)
⚡ Contains scripts (2)
Detected Patterns
Jul 7, 2026, 08:59 PM
Most static findings are false positives caused by defensive Velociraptor examples, VQL detection patterns, MITRE terminology, and placeholder configuration. I confirmed risks in the deployment and CI guidance, including remote script execution, privileged service installation, broad network binding, temporary client config handling, webhook secret placement, and insecure NFS guidance. No prompt injection attempt was found in the reviewed files.
Confirmed security concerns (5)
Capability review items (32)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (54)
⚙️ External commands (99)
📁 Filesystem access (3)
🔑 Env variables (25)
⚡ Contains scripts (2)
Detected Patterns
Jul 6, 2026, 12:42 AM
Most static detections are defensive Velociraptor, MITRE, and security-rule examples rather than hidden malicious behavior. Confirmed risks are concentrated in operational templates: curl-to-shell CI installation, privileged service and firewall commands, broad network binding, /tmp client configuration output, and broad endpoint collection defaults.
Confirmed security concerns (5)
Capability review items (33)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (35)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (54)
⚙️ External commands (99)
📁 Filesystem access (3)
🔑 Env variables (25)
⚡ Contains scripts (2)
Detected Patterns
Jun 28, 2026, 05:41 AM
Static findings are mostly explained by the skill being a Velociraptor DFIR guide, not by hidden malicious code. However, the content includes templates for broad endpoint collection, credential-adjacent artifact discovery, privileged service deployment, webhook notification, and shell-based installation patterns, so publication should require human review and strong warnings.
Confirmed security concerns (7)
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (4)
⚙️ External commands (4)
📁 Filesystem access (3)
🔑 Env variables (3)
⚡ Contains scripts (2)
Detected Patterns
Jan 16, 2026, 03:43 PM
Pure documentation skill containing only markdown reference files and YAML templates for the legitimate open-source Velociraptor DFIR platform. All patterns detected are false positives: VQL queries (not shell commands), detection patterns (not C2 code), forensic artifacts (not credential theft), and documentation links. This is incident response documentation for security professionals.
Risk Factors
🌐 Network access (55)
⚙️ External commands (424)
📁 Filesystem access (3)
🔑 Env variables (29)
⚡ Contains scripts (2)
Jan 16, 2026, 03:43 PM
Pure documentation skill containing only markdown reference files and YAML templates for the legitimate open-source Velociraptor DFIR platform. All patterns detected are false positives: VQL queries (not shell commands), detection patterns (not C2 code), forensic artifacts (not credential theft), and documentation links. This is incident response documentation for security professionals.
Risk Factors
🌐 Network access (55)
⚙️ External commands (424)
📁 Filesystem access (3)
🔑 Env variables (29)
⚡ Contains scripts (2)
Jan 10, 2026, 10:42 AM
Pure documentation skill containing only markdown reference files and YAML templates. No executable code, no network calls, no file system access, no command execution. Legitimate Velociraptor DFIR documentation for incident response professionals.
Jan 10, 2026, 10:42 AM
Pure documentation skill containing only markdown reference files and YAML templates. No executable code, no network calls, no file system access, no command execution. Legitimate Velociraptor DFIR documentation for incident response professionals.
Jan 10, 2026, 10:42 AM
Pure documentation skill containing only markdown reference files and YAML templates. No executable code, no network calls, no file system access, no command execution. Legitimate Velociraptor DFIR documentation for incident response professionals.