📦

Audit History

epistemic-checkpoint - 9 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v9 LatestJul 6, 2026, 03:12 AM No confirmed findings0No capability change
v8 Jul 6, 2026, 03:12 AM No confirmed findings0External commands Filesystem accessNetwork access
v7 Jun 28, 2026, 08:26 AM No confirmed findings1Filesystem accessNetwork access External commands
v6 Jan 21, 2026, 03:33 PM No confirmed findings0No capability change
v5 Jan 16, 2026, 04:07 PM No confirmed findings0No capability change
v4 Jan 16, 2026, 04:07 PM No confirmed findings0External commands
v3 Jan 10, 2026, 09:48 AM No confirmed findings0No capability change
v2 Jan 10, 2026, 09:48 AM No confirmed findings0No capability change
v1 Jan 10, 2026, 09:48 AM No confirmed findings0Baseline

Jul 6, 2026, 03:12 AM

The static findings are false positives caused by Markdown code fences and examples in SKILL.md, not executable Ruby or shell code. The line flagged for system reconnaissance is a verification reminder, not host or environment enumeration. No prompt injection, data exfiltration, or malicious intent was found.

1
Files scanned
128
Lines analyzed
1
Review items
0
False positives ignored
Audited by: codex

Jul 6, 2026, 03:12 AM

The static findings are false positives caused by Markdown code fences and examples in SKILL.md, not executable Ruby or shell code. The line flagged for system reconnaissance is a verification reminder, not host or environment enumeration. No prompt injection, data exfiltration, or malicious intent was found.

1
Files scanned
128
Lines analyzed
1
Review items
0
False positives ignored
Audited by: codex

Jun 28, 2026, 08:26 AM

Static command-execution and blocker alerts were false positives. The file contains fenced text examples and instructions to use local assertions and WebSearch, but no executable scripts, shell calls, weak cryptography, or prompt injection were found.

1
Files scanned
128
Lines analyzed
3
Review items
3
False positives ignored
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Low
Uses Local File Read and Web Search
The skill instructs the assistant to read a local assertions file and use WebSearch for current facts. This is expected behavior for the skill, but users should understand that it may access local project knowledge and external sources.
The instructions explicitly name a local assertions file and WebSearch. The behavior is limited to verification and shows no exfiltration intent.
Static false positives ignored (3)

These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.

Low
Fenced Text Misidentified as Command Execution
The static Ruby or shell backtick detections are false positives. The cited areas are Markdown fenced text blocks and example response text, not executable code or scripts.
The reviewed locations are inside SKILL.md Markdown examples. No Ruby code, shell backticks, subprocess calls, or executable files are present.
Low
Weak Cryptography Alert Is Not Supported
The high-severity weak cryptographic algorithm alert at the metadata description is a false positive. The cited line contains descriptive YAML metadata and no hash, cipher, or cryptographic API usage.
Line 3 begins the skill description block. There is no cryptographic term or implementation at that location.
Low
System Reconnaissance Alert Is Not Supported
The system reconnaissance alert is a false positive. The cited line advises verification when user-provided release status may be wrong, and it does not inspect host, process, network, or account details.
The line is a table entry about factual verification. No system inventory, environment probing, or reconnaissance command is present.

Risk Factors

📁 Filesystem access (1)
🌐 Network access (1)
Audited by: codex

Jan 21, 2026, 03:33 PM

All 21 static findings are false positives. The skill is a legitimate metacognitive guard for hallucination prevention. Network access (WebSearch) is controlled and intentional for fact verification. All "external_commands" detections are documentation examples in markdown, not actual shell execution.

2
Files scanned
420
Lines analyzed
1
Review items
0
False positives ignored
Audited by: claude

Jan 16, 2026, 04:07 PM

AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.

2
Files scanned
305
Lines analyzed
1
Review items
0
False positives ignored

Detected Patterns

Weak cryptographic algorithmRuby/shell backtick executionSystem reconnaissance
Audited by: claude

Jan 16, 2026, 04:07 PM

AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.

2
Files scanned
305
Lines analyzed
1
Review items
0
False positives ignored

Detected Patterns

Weak cryptographic algorithmRuby/shell backtick executionSystem reconnaissance
Audited by: claude

Jan 10, 2026, 09:48 AM

Pure prompt-based skill with no code execution capabilities. Only provides behavioral guidelines for Claude to follow when answering version and date questions. No scripts, network calls, file writes, or external command execution.

1
Files scanned
128
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 10, 2026, 09:48 AM

Pure prompt-based skill with no code execution capabilities. Only provides behavioral guidelines for Claude to follow when answering version and date questions. No scripts, network calls, file writes, or external command execution.

1
Files scanned
128
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 10, 2026, 09:48 AM

Pure prompt-based skill with no code execution capabilities. Only provides behavioral guidelines for Claude to follow when answering version and date questions. No scripts, network calls, file writes, or external command execution.

1
Files scanned
128
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude