Audit History
json-validator - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 23, 2026, 05:26 AM | No confirmed findings | 0 | No capability change |
| v8 | Jul 7, 2026, 06:16 PM | No confirmed findings | 0 | No capability change |
| v7 | Jul 6, 2026, 03:35 AM | No confirmed findings | 0 | External commands |
| v6 | Jun 28, 2026, 08:15 AM | No confirmed findings | 0 | External commands |
| v5 | Jan 16, 2026, 03:24 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 03:24 PM | No confirmed findings | 0 | External commands |
| v3 | Jan 10, 2026, 10:16 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 10:16 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 10:16 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 05:26 AM
All 27 static alerts are false positives caused by Markdown code fences, JSON comments, or ordinary explanatory wording. The skill contains no command execution, system reconnaissance, prompt injection, or other harmful intent.
Risk Factors
⚙️ External commands (21)
Jul 7, 2026, 06:16 PM
Static analysis flagged Markdown code fences and documentation phrases as command execution or reconnaissance. Review of SKILL.md found only JSON validation guidance, formatting examples, and conversion examples, with no executable commands or prompt injection evidence.
Risk Factors
⚙️ External commands (21)
Jul 6, 2026, 03:35 AM
All static findings were false positives caused by Markdown code fences, JSON examples, or prose about JSON validation. I found no prompt injection, command execution intent, data exfiltration, or host reconnaissance in SKILL.md.
Risk Factors
⚙️ External commands (21)
Jun 28, 2026, 08:15 AM
Static analysis reported external command, weak cryptography, and reconnaissance patterns, but the reviewed locations are Markdown prose or fenced JSON/YAML examples. No executable code, shell command construction, cryptographic implementation, reconnaissance logic, network calls, environment access, or prompt injection text was found. The skill is safe to publish with the static findings dismissed as false positives.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Jan 16, 2026, 03:24 PM
This is a pure prompt-based skill with no code execution, file access, or network capabilities. The skill provides only instructions for AI agents to help users validate, format, and fix JSON data. All 41 static findings are false positives caused by keyword-based pattern detection misinterpreting markdown documentation as security threats.
Risk Factors
⚙️ External commands (21)
Jan 16, 2026, 03:24 PM
This is a pure prompt-based skill with no code execution, file access, or network capabilities. The skill provides only instructions for AI agents to help users validate, format, and fix JSON data. All 41 static findings are false positives caused by keyword-based pattern detection misinterpreting markdown documentation as security threats.
Risk Factors
⚙️ External commands (21)
Jan 10, 2026, 10:16 AM
This is a pure prompt-based skill with no code execution, file access, or network capabilities. The skill provides only instructions for AI agents to help users validate, format, and fix JSON data.
Jan 10, 2026, 10:16 AM
This is a pure prompt-based skill with no code execution, file access, or network capabilities. The skill provides only instructions for AI agents to help users validate, format, and fix JSON data.
Jan 10, 2026, 10:16 AM
This is a pure prompt-based skill with no code execution, file access, or network capabilities. The skill provides only instructions for AI agents to help users validate, format, and fix JSON data.