Audit History
reviewdog - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 23, 2026, 06:21 AM | 3 confirmed | 4 | No capability change |
| v8 | Jul 7, 2026, 09:33 PM | 1 confirmed | 4 | No capability change |
| v7 | Jul 6, 2026, 01:08 AM | 1 confirmed | 3 | No capability change |
| v6 | Jun 28, 2026, 06:01 AM | 1 confirmed | 2 | Filesystem accessNetwork accessContains scripts |
| v5 | Jan 16, 2026, 03:58 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 03:58 PM | No confirmed findings | 0 | No capability change |
| v3 | Jan 10, 2026, 10:55 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 10:55 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 10:55 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 06:21 AM
Most static alerts are false positives caused by Markdown code spans, documentation URLs, /dev/null redirection, and references to platform-managed CI tokens. The GitLab template critically downloads a mutable remote installer and pipes it directly to sh. The templates also use predictable temporary files, unpinned CI dependencies, and fail-open secret-scanning patterns.
Confirmed security concerns (3)
Capability review items (4)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
📁 Filesystem access (34)
🔑 Env variables (17)
🌐 Network access (19)
⚡ Contains scripts (2)
⚙️ External commands (49)
Detected Patterns
Jul 7, 2026, 09:33 PM
The skill is primarily documentation and CI templates for reviewdog-based security scanning. Most static findings are expected scanner commands, CI token references, or security reference examples. The GitLab CI template contains a confirmed pipe-to-shell remote installer, and fixed /tmp Gitleaks paths should be replaced.
Confirmed security concerns (1)
Capability review items (4)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
📁 Filesystem access (34)
🔑 Env variables (17)
🌐 Network access (19)
⚡ Contains scripts (2)
⚙️ External commands (49)
Detected Patterns
Jul 6, 2026, 01:08 AM
I found no evidence of prompt injection or malicious data exfiltration in the skill text. Most static alerts are safe documentation examples or expected reviewdog CI configuration. Confirmed risks are the GitLab CI remote installer pipe-to-shell pattern and a predictable temporary Gitleaks report path.
Confirmed security concerns (1)
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
📁 Filesystem access (21)
🔑 Env variables (17)
🌐 Network access (19)
⚡ Contains scripts (2)
⚙️ External commands (49)
Detected Patterns
Jun 28, 2026, 06:01 AM
Static analysis found many command, network, filesystem, and token patterns. Most are expected for a reviewdog CI integration skill, but the GitLab template includes a confirmed curl-to-shell installer pattern that should be remediated before publication. No prompt injection or confirmed malicious exfiltration intent was found.
Confirmed security concerns (1)
Needs review findings (2)
These findings came from uncertain legacy audit verdicts, so they require review but are not counted as confirmed security issues.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
📁 Filesystem access (23)
🔑 Env variables (17)
🌐 Network access (29)
⚡ Contains scripts (2)
⚙️ External commands (219)
Detected Patterns
Jan 16, 2026, 03:58 PM
Documentation-only skill containing CI/CD templates and reference materials for reviewdog security integration. All static findings are false positives from legitimate DevSecOps documentation. The skill describes running security scanners (Semgrep, Bandit, Gitleaks) and posting results to PRs - this is standard, documented CI/CD behavior using properly secured token management via GitHub/GitLab secrets.
Risk Factors
⚙️ External commands (3)
🔑 Env variables (3)
Jan 16, 2026, 03:58 PM
Documentation-only skill containing CI/CD templates and reference materials for reviewdog security integration. All static findings are false positives from legitimate DevSecOps documentation. The skill describes running security scanners (Semgrep, Bandit, Gitleaks) and posting results to PRs - this is standard, documented CI/CD behavior using properly secured token management via GitHub/GitLab secrets.
Risk Factors
⚙️ External commands (3)
🔑 Env variables (3)
Jan 10, 2026, 10:55 AM
Documentation and configuration-only skill. Contains YAML templates and reference docs for integrating reviewdog security scanning. No executable scripts present. All described functionality is legitimate DevSecOps tooling.
Risk Factors
⚙️ External commands (2)
🔑 Env variables (2)
Jan 10, 2026, 10:55 AM
Documentation and configuration-only skill. Contains YAML templates and reference docs for integrating reviewdog security scanning. No executable scripts present. All described functionality is legitimate DevSecOps tooling.
Risk Factors
⚙️ External commands (2)
🔑 Env variables (2)
Jan 10, 2026, 10:55 AM
Documentation and configuration-only skill. Contains YAML templates and reference docs for integrating reviewdog security scanning. No executable scripts present. All described functionality is legitimate DevSecOps tooling.