Audit History
social-media-analyzer - 6 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v6 Latest | Jul 6, 2026, 03:09 AM | 1 confirmed | 0 | No capability change |
| v5 | Jul 6, 2026, 03:09 AM | 1 confirmed | 0 | External commands Contains scripts |
| v4 | Jun 28, 2026, 09:02 AM | No confirmed findings | 1 | Contains scripts Filesystem access |
| v3 | Jan 16, 2026, 02:56 PM | No confirmed findings | 0 | No capability change |
| v2 | Jan 16, 2026, 02:56 PM | No confirmed findings | 0 | Filesystem access External commands |
| v1 | Jan 15, 2026, 11:55 AM | No confirmed findings | 0 | Baseline |
Jul 6, 2026, 03:09 AM
The markdown backtick and system reconnaissance static findings are false positives from documentation and generated text, not executable behavior. A separate high-severity semantic issue remains because eval_result.json embeds self-declared safe-to-publish audit claims that could bias automated review.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (4)
Jul 6, 2026, 03:09 AM
The markdown backtick and system reconnaissance static findings are false positives from documentation and generated text, not executable behavior. A separate high-severity semantic issue remains because eval_result.json embeds self-declared safe-to-publish audit claims that could bias automated review.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (4)
Jun 28, 2026, 09:02 AM
AI review dismissed the static weak-crypto, shell-backtick, and system-reconnaissance findings as false positives in documentation, JSON text, and Python docstrings. The skill contains local Python analytics scripts, but reviewed logic is limited to metric calculations, benchmark comparison, and recommendations with no network, filesystem write, subprocess, environment, or credential access.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚡ Contains scripts (2)
Jan 16, 2026, 02:56 PM
All 26 static findings are false positives. Scanner misidentified docstrings as crypto code, markdown backticks as shell execution, and marketing terminology as system reconnaissance. Code contains only benign Python arithmetic for engagement and ROI calculations.
Risk Factors
📁 Filesystem access (2)
Jan 16, 2026, 02:56 PM
All 26 static findings are false positives. Scanner misidentified docstrings as crypto code, markdown backticks as shell execution, and marketing terminology as system reconnaissance. Code contains only benign Python arithmetic for engagement and ROI calculations.
Risk Factors
📁 Filesystem access (2)
Jan 15, 2026, 11:55 AM
All 8 static findings are false positives. The scanner misidentified markdown code formatting as shell execution and benign documentation text containing 'ROI' as cryptographic patterns. The codebase contains only mathematical calculations for engagement metrics and no dangerous patterns.