Audit History
allra-error-handling - 10 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v10 Latest | Jul 23, 2026, 05:19 AM | 1 confirmed | 0 | No capability change |
| v9 | Jul 7, 2026, 06:10 PM | 2 confirmed | 0 | No capability change |
| v8 | Jul 5, 2026, 03:08 AM | 2 confirmed | 0 | External commands |
| v7 | Jun 28, 2026, 09:29 AM | 1 confirmed | 0 | No capability change |
| v6 | Jan 21, 2026, 03:21 PM | No confirmed findings | 0 | External commands |
| v5 | Jan 16, 2026, 03:19 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 03:19 PM | No confirmed findings | 0 | External commands |
| v3 | Jan 10, 2026, 10:18 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 10:18 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 10:18 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 05:19 AM
All 21 static findings are false positives caused by Markdown code fences or ordinary Java identifiers; the skill executes no external commands. One medium-severity design concern remains because examples may expose personal or sensitive values through logs and validation responses.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (19)
Jul 7, 2026, 06:10 PM
All static external command and blocker detections are false positives from Markdown fences and Java examples. No executable shell code or system reconnaissance instruction is present. Two semantic issues remain: logging email addresses and returning rejected input values may expose personal data.
Confirmed security concerns (2)
Risk Factors
⚙️ External commands (19)
Jul 5, 2026, 03:08 AM
Most static command-execution findings are false positives caused by Markdown code fences in Java and JSON examples. I found no prompt injection or malicious execution intent in SKILL.md. Two semantic privacy issues remain: validation responses echo rejected values and logging examples include raw email addresses.
Confirmed security concerns (2)
Risk Factors
⚙️ External commands (19)
Jun 28, 2026, 09:29 AM
The static external command findings are false positives caused by markdown code fences in SKILL.md, not executable shell or Ruby code. The weak cryptography and reconnaissance alerts are also false positives from normal prose or Java examples. A moderate issue remains because examples show rejected values and email addresses in responses or logs, which can expose personal data if copied directly.
Confirmed security concerns (1)
Detected Patterns
Jan 21, 2026, 03:21 PM
All static findings are false positives. The skill is a documentation-only skill containing Java code examples for error handling patterns. No actual security risks present.
Jan 16, 2026, 03:19 PM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
⚙️ External commands (19)
Detected Patterns
Jan 16, 2026, 03:19 PM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
⚙️ External commands (19)
Detected Patterns
Jan 10, 2026, 10:18 AM
Pure documentation skill containing only markdown with Java code templates for error handling. No executable code, scripts, network calls, or filesystem access. Contains no security concerns.
Jan 10, 2026, 10:18 AM
Pure documentation skill containing only markdown with Java code templates for error handling. No executable code, scripts, network calls, or filesystem access. Contains no security concerns.
Jan 10, 2026, 10:18 AM
Pure documentation skill containing only markdown with Java code templates for error handling. No executable code, scripts, network calls, or filesystem access. Contains no security concerns.