Audit History
planning-with-files - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 6, 2026, 02:52 AM | No confirmed findings | 0 | No capability change |
| v7 | Jul 6, 2026, 02:52 AM | No confirmed findings | 0 | Filesystem accessNetwork access |
| v6 | Jun 28, 2026, 09:16 AM | 1 confirmed | 0 | Filesystem access |
| v5 | Jan 16, 2026, 03:39 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 03:39 PM | No confirmed findings | 0 | External commandsNetwork access |
| v3 | Jan 10, 2026, 10:17 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 10:17 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 10:17 AM | No confirmed findings | 0 | Baseline |
Jul 6, 2026, 02:52 AM
I found no evidence of executable commands, prompt injection, data exfiltration, or host reconnaissance in the reviewed files. The static command findings are Markdown filenames, code fences, and pseudo agent steps that document a planning workflow. Some pseudo steps are labeled as bash, which may trigger scanners.
Risk Factors
Jul 6, 2026, 02:52 AM
I found no evidence of executable commands, prompt injection, data exfiltration, or host reconnaissance in the reviewed files. The static command findings are Markdown filenames, code fences, and pseudo agent steps that document a planning workflow. Some pseudo steps are labeled as bash, which may trigger scanners.
Risk Factors
Jun 28, 2026, 09:16 AM
Static analysis reported many command-execution patterns, weak-crypto indicators, a browser-storage reference, reconnaissance indicators, and one hardcoded URL. Manual review found these are markdown examples and documentation text, not executable code or instructions to exfiltrate data. The skill does encourage creating, reading, and editing local markdown files, so the main residual risk is expected filesystem use during workflow planning.
Confirmed security concerns (1)
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
📁 Filesystem access (6)
⚙️ External commands (5)
🌐 Network access (2)
Jan 16, 2026, 03:39 PM
Pure documentation skill containing only markdown files with workflow guidance. No executable code, scripts, network calls, or file system operations. The static analyzer misinterpreted markdown inline code formatting (backticks) as shell command execution patterns. All 68 findings are false positives.
Risk Factors
⚙️ External commands (50)
🌐 Network access (1)
Jan 16, 2026, 03:39 PM
Pure documentation skill containing only markdown files with workflow guidance. No executable code, scripts, network calls, or file system operations. The static analyzer misinterpreted markdown inline code formatting (backticks) as shell command execution patterns. All 68 findings are false positives.
Risk Factors
⚙️ External commands (50)
🌐 Network access (1)
Jan 10, 2026, 10:17 AM
Pure prompt-based skill with no executable code. All content is documentation and workflow guidance for markdown file management. No scripts, network calls, file system access, environment variables, or external commands detected.
Jan 10, 2026, 10:17 AM
Pure prompt-based skill with no executable code. All content is documentation and workflow guidance for markdown file management. No scripts, network calls, file system access, environment variables, or external commands detected.
Jan 10, 2026, 10:17 AM
Pure prompt-based skill with no executable code. All content is documentation and workflow guidance for markdown file management. No scripts, network calls, file system access, environment variables, or external commands detected.