Audit History
Roadmap Planning Expert - 11 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v11 Latest | Jul 18, 2026, 10:04 AM | No confirmed findings | 0 | No capability change |
| v10 | Jul 18, 2026, 12:12 AM | No confirmed findings | 0 | No capability change |
| v9 | Jul 7, 2026, 08:07 PM | 1 confirmed | 0 | No capability change |
| v8 | Jul 6, 2026, 03:33 AM | No confirmed findings | 0 | External commands |
| v7 | Jun 28, 2026, 08:57 AM | No confirmed findings | 0 | No capability change |
| v6 | Jan 21, 2026, 03:52 PM | No confirmed findings | 0 | External commands |
| v5 | Jan 16, 2026, 04:52 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 04:52 PM | No confirmed findings | 0 | External commands |
| v3 | Jan 10, 2026, 10:19 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 10:19 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 10:19 AM | No confirmed findings | 0 | Baseline |
Jul 18, 2026, 10:04 AM
All 18 static findings are false positives caused by Markdown backticks in diagrams, file names, and documented slash commands. The skill contains planning guidance only; no executable shell or Ruby code, network instructions, or prompt-injection language was found.
Risk Factors
Jul 18, 2026, 12:12 AM
All 18 static findings are false positives caused by Markdown fenced or inline code formatting, not Ruby or shell backtick execution. SKILL.md contains planning guidance and names companion slash commands, but it includes no executable code, credential access, or prompt injection. No security remediation is required.
Risk Factors
Jul 7, 2026, 08:07 PM
All 18 static external command alerts are false positives from Markdown code fences, inline file names, and documented slash commands. No prompt injection or executable shell instructions were found in SKILL.md. The remaining concern is the documented ClickUp synchronization, which should require explicit user consent before sharing roadmap data.
Confirmed security concerns (1)
Risk Factors
Jul 6, 2026, 03:33 AM
All static findings are false positives caused by Markdown code fences and inline backticks in SKILL.md. The skill contains planning guidance, file naming conventions, and slash command references, with no evidence of executable shell code, prompt injection, or data exfiltration intent.
Risk Factors
Jun 28, 2026, 08:57 AM
Static analysis reported external command and weak cryptography patterns, but review found these are false positives in Markdown guidance. The flagged lines contain code fences, inline file names, and slash-command documentation, with no executable scripts, network calls, prompt injection, or secret access found.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Jan 21, 2026, 03:52 PM
This is a documentation-only skill providing strategic planning guidance and methodology. All static findings are false positives from markdown code examples. No executable code, network calls, or file operations detected. Safe for publication.
Jan 16, 2026, 04:52 PM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
Detected Patterns
Jan 16, 2026, 04:52 PM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
Detected Patterns
Jan 10, 2026, 10:19 AM
This is a declarative SKILL.md training document containing only markdown-based expertise guidance. No executable code, scripts, network operations, or filesystem access beyond configuration. Pure prompt-based skill for training AI on strategic planning methodology.
Jan 10, 2026, 10:19 AM
This is a declarative SKILL.md training document containing only markdown-based expertise guidance. No executable code, scripts, network operations, or filesystem access beyond configuration. Pure prompt-based skill for training AI on strategic planning methodology.
Jan 10, 2026, 10:19 AM
This is a declarative SKILL.md training document containing only markdown-based expertise guidance. No executable code, scripts, network operations, or filesystem access beyond configuration. Pure prompt-based skill for training AI on strategic planning methodology.