Audit History
quality-manager-qmr - 6 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v6 Latest | Jul 6, 2026, 01:53 AM | No confirmed findings | 0 | No capability change |
| v5 | Jul 6, 2026, 01:53 AM | No confirmed findings | 0 | Env variablesExternal commands |
| v4 | Jun 28, 2026, 09:29 AM | No confirmed findings | 0 | External commandsEnv variables |
| v3 | Jan 16, 2026, 04:34 PM | No confirmed findings | 0 | No capability change |
| v2 | Jan 16, 2026, 04:34 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 15, 2026, 11:40 AM | No confirmed findings | 0 | Baseline |
Jul 6, 2026, 01:53 AM
All static findings were assessed as false positives after reviewing the referenced skill text and evaluation content. The flagged external command items are markdown fences or inline file and directory names, while environment and reconnaissance items are ordinary QMR governance prose with no executable behavior.
Risk Factors
🔑 Env variables (4)
Jul 6, 2026, 01:53 AM
All static findings were assessed as false positives after reviewing the referenced skill text and evaluation content. The flagged external command items are markdown fences or inline file and directory names, while environment and reconnaissance items are ordinary QMR governance prose with no executable behavior.
Risk Factors
🔑 Env variables (4)
Jun 28, 2026, 09:29 AM
The static analyzer reported many high-risk patterns, but the cited lines are documentation, markdown formatting, or prior evaluation text. I found no evidence of prompt injection, credential access, network calls, weak cryptography, or command execution intent in the reviewed files.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Jan 16, 2026, 04:34 PM
This is a documentation-only skill containing markdown files with quality management frameworks. No executable code, scripts, network operations, or cryptographic operations exist. All 63 static findings are false positives caused by the scanner misidentifying ASCII tree diagram characters as shell backticks, file format names as cryptographic patterns, and regulatory compliance text as security threats.
Risk Factors
⚙️ External commands (2)
🔑 Env variables (1)
Jan 16, 2026, 04:34 PM
This is a documentation-only skill containing markdown files with quality management frameworks. No executable code, scripts, network operations, or cryptographic operations exist. All 63 static findings are false positives caused by the scanner misidentifying ASCII tree diagram characters as shell backticks, file format names as cryptographic patterns, and regulatory compliance text as security threats.
Risk Factors
⚙️ External commands (2)
🔑 Env variables (1)
Jan 15, 2026, 11:40 AM
Documentation-only skill with no executable code. All 24 static findings are false positives: ASCII art tree diagrams (Unicode box characters) misinterpreted as shell backticks, file format names misinterpreted as cryptographic algorithms, and regulatory compliance text misinterpreted as network reconnaissance.