Audit History
sca-trivy - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 23, 2026, 06:59 AM | 3 confirmed | 0 | No capability change |
| v8 | Jul 7, 2026, 10:08 PM | No confirmed findings | 0 | No capability change |
| v7 | Jul 5, 2026, 01:11 AM | 2 confirmed | 0 | No capability change |
| v6 | Jun 28, 2026, 06:21 AM | No confirmed findings | 4 | No capability change |
| v5 | Jan 16, 2026, 04:16 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 04:16 PM | No confirmed findings | 0 | Network accessExternal commandsFilesystem access |
| v3 | Jan 10, 2026, 11:02 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 11:02 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 11:02 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 06:59 AM
All 73 static findings are false positives caused by Markdown code fences, inline code, reference links, and documented configuration paths. Semantic review found mutable CI references, credential exposure guidance, and an ineffective custom-policy gate. These examples require hardening before publication.
Confirmed security concerns (3)
Risk Factors
⚙️ External commands (50)
🌐 Network access (10)
📁 Filesystem access (2)
Jul 7, 2026, 10:08 PM
The static findings are false positives caused by Markdown command examples, inline filenames, sample configuration, and reference URLs. No packaged executable files, prompt injection text, credential exfiltration intent, or hidden network behavior were found in SKILL.md.
Risk Factors
⚙️ External commands (61)
🌐 Network access (10)
📁 Filesystem access (2)
Jul 5, 2026, 01:11 AM
The 73 static findings are false positives from Markdown command formatting, reference URLs, and sample configuration text. No prompt injection or malicious exfiltration intent was found, but two documentation risks remain in the CI and credential examples.
Confirmed security concerns (2)
Risk Factors
⚙️ External commands (61)
🌐 Network access (10)
📁 Filesystem access (2)
Jun 28, 2026, 06:21 AM
Static analysis found many shell-command examples, network URLs, filesystem paths, and high-risk keywords. Review found no prompt injection, malware intent, data exfiltration, or hidden execution; most high-risk hits are false positives from security terminology and documentation. The skill still warrants a medium warning because it instructs users to run Trivy, Docker, CI actions, filesystem scans, and credential-related commands.
Capability review items (4)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (5)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (61)
🌐 Network access (10)
📁 Filesystem access (2)
Detected Patterns
Jan 16, 2026, 04:16 PM
Documentation-only skill containing markdown guides for Trivy vulnerability scanner usage. No executable code present. This is a knowledge-base skill providing standardized workflows for identifying CVEs, generating SBOMs, and integrating security scanning into CI/CD pipelines. All 86 static findings are false positives - the analyzer misinterpreted documentation examples and legitimate security/compliance terminology as security threats.
Risk Factors
🌐 Network access (10)
⚙️ External commands (61)
📁 Filesystem access (2)
Jan 16, 2026, 04:16 PM
Documentation-only skill containing markdown guides for Trivy vulnerability scanner usage. No executable code present. This is a knowledge-base skill providing standardized workflows for identifying CVEs, generating SBOMs, and integrating security scanning into CI/CD pipelines. All 86 static findings are false positives - the analyzer misinterpreted documentation examples and legitimate security/compliance terminology as security threats.
Risk Factors
🌐 Network access (10)
⚙️ External commands (61)
📁 Filesystem access (2)
Jan 10, 2026, 11:02 AM
Pure documentation-only skill containing markdown guides for Trivy vulnerability scanner usage. No executable code present. This is a knowledge-base skill with no file access, network operations, or command execution capabilities.
Jan 10, 2026, 11:02 AM
Pure documentation-only skill containing markdown guides for Trivy vulnerability scanner usage. No executable code present. This is a knowledge-base skill with no file access, network operations, or command execution capabilities.
Jan 10, 2026, 11:02 AM
Pure documentation-only skill containing markdown guides for Trivy vulnerability scanner usage. No executable code present. This is a knowledge-base skill with no file access, network operations, or command execution capabilities.