Audit History
allra-api-design - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 23, 2026, 05:14 AM | No confirmed findings | 0 | No capability change |
| v8 | Jul 7, 2026, 06:03 PM | No confirmed findings | 0 | No capability change |
| v7 | Jul 6, 2026, 03:25 AM | No confirmed findings | 0 | External commands |
| v6 | Jun 28, 2026, 09:23 AM | No confirmed findings | 0 | External commands |
| v5 | Jan 16, 2026, 03:11 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 03:11 PM | No confirmed findings | 0 | External commands |
| v3 | Jan 10, 2026, 10:16 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 10:16 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 10:16 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 05:14 AM
All 31 static findings are false positives caused by Markdown backticks, fenced examples, and ordinary Java request parameters. The skill is a documentation-only API design guide with no command execution, system reconnaissance, or prompt injection behavior.
Risk Factors
βοΈ External commands (26)
Jul 7, 2026, 06:03 PM
All static findings are false positives caused by Markdown backticks, Java code fences, JSON examples, and Spring controller sample code. The skill is documentation-only and does not ask the agent to execute commands, inspect the host, or send data externally. No prompt injection or semantic abuse evidence was found in SKILL.md.
Risk Factors
βοΈ External commands (26)
Jul 6, 2026, 03:25 AM
All static findings are false positives caused by Markdown backticks, Java examples, JSON examples, and Spring controller method signatures. I found no prompt injection, executable shell commands, data exfiltration behavior, or system reconnaissance intent in SKILL.md.
Risk Factors
βοΈ External commands (26)
Jun 28, 2026, 09:23 AM
Static analysis reported external command, weak cryptography, and reconnaissance patterns in SKILL.md. Manual review found these are false positives from Markdown code fences, inline examples, and descriptive text. No executable scripts, network access, filesystem access, prompt injection, or malicious intent were found.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Jan 16, 2026, 03:11 PM
Pure documentation skill containing only API design guidelines. Static scanner produced false positives: 36 'weak cryptographic algorithm' flags are Java 'record' class definitions; 31 'shell backtick execution' flags are markdown code formatting; 5 'system reconnaissance' flags are Spring @PathVariable annotations. No executable code, network access, file system access, or external commands.
Risk Factors
βοΈ External commands (31)
Jan 16, 2026, 03:11 PM
Pure documentation skill containing only API design guidelines. Static scanner produced false positives: 36 'weak cryptographic algorithm' flags are Java 'record' class definitions; 31 'shell backtick execution' flags are markdown code formatting; 5 'system reconnaissance' flags are Spring @PathVariable annotations. No executable code, network access, file system access, or external commands.
Risk Factors
βοΈ External commands (31)
Jan 10, 2026, 10:16 AM
Pure prompt-based documentation skill containing only API design guidelines. No executable code, no network access, no file system access, no external commands. This skill provides documentation for Java Spring Boot developers and presents no security risk.
Jan 10, 2026, 10:16 AM
Pure prompt-based documentation skill containing only API design guidelines. No executable code, no network access, no file system access, no external commands. This skill provides documentation for Java Spring Boot developers and presents no security risk.
Jan 10, 2026, 10:16 AM
Pure prompt-based documentation skill containing only API design guidelines. No executable code, no network access, no file system access, no external commands. This skill provides documentation for Java Spring Boot developers and presents no security risk.