Audit History
sbom-syft - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 23, 2026, 06:47 AM | 4 confirmed | 3 | No capability change |
| v8 | Jul 7, 2026, 09:55 PM | 3 confirmed | 2 | No capability change |
| v7 | Jul 5, 2026, 03:20 AM | 2 confirmed | 1 | No capability change |
| v6 | Jun 28, 2026, 06:14 AM | 2 confirmed | 0 | No capability change |
| v5 | Jan 16, 2026, 04:08 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 04:08 PM | No confirmed findings | 0 | External commandsNetwork accessFilesystem accessEnv variablesContains scripts |
| v3 | Jan 10, 2026, 11:00 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 11:00 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 11:00 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 06:47 AM
Most detections are false positives caused by Markdown formatting, defensive examples, or fixed local operations. The template still includes a critical pipe-to-shell installer and instructions that download mutable artifacts without integrity verification. It also exposes a GitHub token to an unpinned action and contains CI controls that can fail open.
Confirmed security concerns (4)
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (50)
🌐 Network access (24)
📁 Filesystem access (4)
🔑 Env variables (23)
⚡ Contains scripts (2)
Detected Patterns
Jul 7, 2026, 09:55 PM
Most static findings are false positives from Markdown examples, defensive reference material, and public documentation links. Confirmed issues remain in supply chain guidance: an unverified curl-to-bash installer, a mutable binary download, plaintext credential examples, and a mutable CI action reference.
Confirmed security concerns (3)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (80)
🌐 Network access (24)
📁 Filesystem access (4)
🔑 Env variables (23)
⚡ Contains scripts (2)
Detected Patterns
Jul 5, 2026, 03:20 AM
Most static findings are false positives from Markdown examples, reference links, or defensive security templates. The CI template contains a confirmed remote installer piped to bash and unpinned scanner installation guidance that should be hardened before publication.
Confirmed security concerns (2)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (80)
🌐 Network access (24)
📁 Filesystem access (4)
🔑 Env variables (23)
⚡ Contains scripts (2)
Detected Patterns
Jun 28, 2026, 06:14 AM
Static analysis reported many command, network, environment, filesystem, and script patterns. Review found no malicious intent or prompt injection; most findings are documentation examples or CI templates. Two template patterns remain risky if copied into production without hardening: remote script execution through curl to bash and plaintext registry credential examples.
Confirmed security concerns (2)
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (3)
🌐 Network access (3)
📁 Filesystem access (3)
🔑 Env variables (3)
⚡ Contains scripts (2)
Detected Patterns
Jan 16, 2026, 04:08 PM
Documentation-only skill providing SBOM generation guidance using Syft CLI tool. No executable code exists in this skill. Static scanner flagged patterns within markdown documentation and YAML templates containing example commands, CI/CD workflows, and security rule templates. All findings are false positives since this skill only contains documentation and templates for legitimate supply chain security workflows.
Risk Factors
⚙️ External commands (110)
🌐 Network access (24)
📁 Filesystem access (4)
🔑 Env variables (27)
⚡ Contains scripts (2)
Jan 16, 2026, 04:08 PM
Documentation-only skill providing SBOM generation guidance using Syft CLI tool. No executable code exists in this skill. Static scanner flagged patterns within markdown documentation and YAML templates containing example commands, CI/CD workflows, and security rule templates. All findings are false positives since this skill only contains documentation and templates for legitimate supply chain security workflows.
Risk Factors
⚙️ External commands (110)
🌐 Network access (24)
📁 Filesystem access (4)
🔑 Env variables (27)
⚡ Contains scripts (2)
Jan 10, 2026, 11:00 AM
Documentation-only skill providing SBOM generation guidance using Syft. No executable scripts, no network calls, no file system access, and no external commands. Pure informational content teaching users how to use the Syft CLI tool for supply chain security.
Jan 10, 2026, 11:00 AM
Documentation-only skill providing SBOM generation guidance using Syft. No executable scripts, no network calls, no file system access, and no external commands. Pure informational content teaching users how to use the Syft CLI tool for supply chain security.
Jan 10, 2026, 11:00 AM
Documentation-only skill providing SBOM generation guidance using Syft. No executable scripts, no network calls, no file system access, and no external commands. Pure informational content teaching users how to use the Syft CLI tool for supply chain security.