Audit History
tunit - 6 audits
Audit version 6
Latest Medium RiskJun 28, 2026, 08:51 AM
Static analysis reported many external command hits plus weak cryptography and network reconnaissance indicators. Manual review found the weak cryptography and network reconnaissance indicators are false positives from Markdown text, while the external commands are legitimate dotnet test examples. Risk is medium because the skill directs agents to execute local test projects, which can run repository code and start Playwright resources.
Medium Risk Issues (1)
Low Risk Issues (1)
Risk Factors
⚙️ External commands (6)
Detected Patterns
Audit version 5
SafeJan 16, 2026, 04:43 PM
Documentation-only skill containing test execution instructions. Contains bash command examples for running TUnit tests with Playwright. No executable code, no network calls, no file system access beyond standard documentation. Pure prompt-based skill with safe behavior matching stated purpose. All 47 static findings are false positives from pattern matching on documentation text.
Risk Factors
⚙️ External commands (33)
Audit version 4
SafeJan 16, 2026, 04:43 PM
Documentation-only skill containing test execution instructions. Contains bash command examples for running TUnit tests with Playwright. No executable code, no network calls, no file system access beyond standard documentation. Pure prompt-based skill with safe behavior matching stated purpose. All 47 static findings are false positives from pattern matching on documentation text.
Risk Factors
⚙️ External commands (33)
Audit version 3
SafeJan 10, 2026, 10:20 AM
Documentation-only skill containing test execution instructions. No executable code, no network calls, no file system access beyond documentation. Pure prompt-based skill with safe behavior matching stated purpose.
Audit version 2
SafeJan 10, 2026, 10:20 AM
Documentation-only skill containing test execution instructions. No executable code, no network calls, no file system access beyond documentation. Pure prompt-based skill with safe behavior matching stated purpose.
Audit version 1
SafeJan 10, 2026, 10:20 AM
Documentation-only skill containing test execution instructions. No executable code, no network calls, no file system access beyond documentation. Pure prompt-based skill with safe behavior matching stated purpose.