Audit History
allra-test-writing - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 23, 2026, 05:22 AM | No confirmed findings | 0 | No capability change |
| v8 | Jul 7, 2026, 06:13 PM | No confirmed findings | 0 | No capability change |
| v7 | Jul 6, 2026, 03:31 AM | No confirmed findings | 0 | No capability change |
| v6 | Jun 28, 2026, 08:13 AM | 1 confirmed | 0 | No capability change |
| v5 | Jan 16, 2026, 03:22 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 03:22 PM | No confirmed findings | 0 | External commands |
| v3 | Jan 10, 2026, 10:19 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 10:19 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 10:19 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 05:22 AM
All 87 static alerts are false positives caused by Markdown backticks, fenced code samples, safe test method names, and documented test commands. The skill is a testing guide with no executable scripts, automatic command execution, system reconnaissance, or prompt injection.
Risk Factors
โ๏ธ External commands (50)
Jul 7, 2026, 06:13 PM
All 87 static findings are false positives caused by Markdown code fences, inline Java annotations, bash test examples, and Java method names. I found no prompt injection, data exfiltration intent, malware behavior, or automatic command execution in SKILL.md.
Risk Factors
โ๏ธ External commands (70)
Jul 6, 2026, 03:31 AM
All 87 static findings are false positives. The flagged backticks are Markdown fences or inline code, and the blocker hits are Java test method declarations. No prompt injection, exfiltration intent, or executable skill code was found in SKILL.md.
Risk Factors
โ๏ธ External commands (70)
Jun 28, 2026, 08:13 AM
Static analysis reported many external command and blocker patterns, but review found they are markdown backticks, Java examples, and test documentation. No prompt injection, credential access, network exfiltration, or malicious behavior was found. The skill includes benign Gradle and Maven test command examples, so external command risk is retained as a low-risk publication warning.
Confirmed security concerns (1)
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
โ๏ธ External commands (2)
Jan 16, 2026, 03:22 PM
This is a pure documentation skill containing only markdown guidelines for Java/Spring Boot testing standards. The static analyzer flagged 105 'issues' but ALL findings are FALSE POSITIVES. The 'backtick execution' detections are markdown code block delimiters, not Ruby/shell commands. 'C2 keywords' and 'weak crypto' flags are triggered by metadata field names (content_hash, tree_hash) and Java variable names in test examples (execute, trigger, command). No executable code, scripts, or network calls exist. This skill only provides documentation for test writing patterns and is safe for publishing.
Risk Factors
โ๏ธ External commands (72)
Jan 16, 2026, 03:22 PM
This is a pure documentation skill containing only markdown guidelines for Java/Spring Boot testing standards. The static analyzer flagged 105 'issues' but ALL findings are FALSE POSITIVES. The 'backtick execution' detections are markdown code block delimiters, not Ruby/shell commands. 'C2 keywords' and 'weak crypto' flags are triggered by metadata field names (content_hash, tree_hash) and Java variable names in test examples (execute, trigger, command). No executable code, scripts, or network calls exist. This skill only provides documentation for test writing patterns and is safe for publishing.
Risk Factors
โ๏ธ External commands (72)
Jan 10, 2026, 10:19 AM
Pure documentation skill containing only markdown guidelines. No executable code, scripts, network calls, or file system access. Safe for publishing.
Jan 10, 2026, 10:19 AM
Pure documentation skill containing only markdown guidelines. No executable code, scripts, network calls, or file system access. Safe for publishing.
Jan 10, 2026, 10:19 AM
Pure documentation skill containing only markdown guidelines. No executable code, scripts, network calls, or file system access. Safe for publishing.