Audit History
allra-database-schema - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 23, 2026, 05:16 AM | 1 confirmed | 0 | No capability change |
| v8 | Jul 7, 2026, 06:06 PM | 1 confirmed | 0 | No capability change |
| v7 | Jul 6, 2026, 03:28 AM | No confirmed findings | 0 | External commandsNetwork access |
| v6 | Jun 28, 2026, 09:26 AM | 3 confirmed | 0 | Network accessExternal commands |
| v5 | Jan 16, 2026, 03:14 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 03:14 PM | No confirmed findings | 0 | Network accessExternal commands |
| v3 | Jan 10, 2026, 10:17 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 10:17 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 10:17 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 05:16 AM
All 29 static findings are false positives caused by Markdown code fences, inline code, QueryDSL fetch operations, and ordinary Java domain methods. A separate high-severity issue remains because the examples assign a supplied password directly to an entity without demonstrating hashing.
Confirmed security concerns (1)
Risk Factors
โ๏ธ External commands (24)
๐ Network access (3)
Jul 7, 2026, 06:06 PM
The external command, network, and blocker static hits are false positives from Markdown fences, QueryDSL .fetch(), and ordinary Java entity methods. A semantic issue remains: the entity example directly assigns a password value without showing hashing or hash-only storage. No prompt-injection text or executable command behavior was found in SKILL.md.
Confirmed security concerns (1)
Risk Factors
โ๏ธ External commands (24)
๐ Network access (3)
Jul 6, 2026, 03:28 AM
All static findings are false positives caused by markdown code fences, Java annotations, QueryDSL fetch methods, and normal domain methods. No prompt injection, data exfiltration intent, executable shell logic, or unsafe network behavior was found in the reviewed SKILL.md file.
Risk Factors
โ๏ธ External commands (24)
๐ Network access (3)
Jun 28, 2026, 09:26 AM
Static analysis reported external command, network, weak crypto, and reconnaissance patterns, but review found these are false positives in Markdown documentation and Java examples. No executable scripts, network endpoints, credential handling, prompt injection attempts, or malicious intent were found in SKILL.md.
Confirmed security concerns (3)
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Jan 16, 2026, 03:14 PM
Documentation-only skill containing coding standards and guidelines for Java/Spring Boot database development. All 46 static findings are false positives caused by the scanner misidentifying code examples in markdown documentation as executable code, and hash/metadata values triggering pattern matches. No actual executable code, no file system access, no network calls, and no system modifications.
Risk Factors
๐ Network access (3)
โ๏ธ External commands (24)
Jan 16, 2026, 03:14 PM
Documentation-only skill containing coding standards and guidelines for Java/Spring Boot database development. All 46 static findings are false positives caused by the scanner misidentifying code examples in markdown documentation as executable code, and hash/metadata values triggering pattern matches. No actual executable code, no file system access, no network calls, and no system modifications.
Risk Factors
๐ Network access (3)
โ๏ธ External commands (24)
Jan 10, 2026, 10:17 AM
Documentation-only skill containing coding standards and guidelines for Java/Spring Boot database development. No executable code, no file access, no network calls, no system modifications.
Jan 10, 2026, 10:17 AM
Documentation-only skill containing coding standards and guidelines for Java/Spring Boot database development. No executable code, no file access, no network calls, no system modifications.
Jan 10, 2026, 10:17 AM
Documentation-only skill containing coding standards and guidelines for Java/Spring Boot database development. No executable code, no file access, no network calls, no system modifications.