📦

Audit History

Roadmap Planning Expert - 11 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v11 LatestJul 18, 2026, 10:04 AM No confirmed findings0No capability change
v10 Jul 18, 2026, 12:12 AM No confirmed findings0No capability change
v9 Jul 7, 2026, 08:07 PM 1 confirmed0No capability change
v8 Jul 6, 2026, 03:33 AM No confirmed findings0External commands
v7 Jun 28, 2026, 08:57 AM No confirmed findings0No capability change
v6 Jan 21, 2026, 03:52 PM No confirmed findings0 External commands
v5 Jan 16, 2026, 04:52 PM No confirmed findings0No capability change
v4 Jan 16, 2026, 04:52 PM No confirmed findings0External commands
v3 Jan 10, 2026, 10:19 AM No confirmed findings0No capability change
v2 Jan 10, 2026, 10:19 AM No confirmed findings0No capability change
v1 Jan 10, 2026, 10:19 AM No confirmed findings0Baseline

Jul 18, 2026, 10:04 AM

All 18 static findings are false positives caused by Markdown backticks in diagrams, file names, and documented slash commands. The skill contains planning guidance only; no executable shell or Ruby code, network instructions, or prompt-injection language was found.

1
Files scanned
107
Lines analyzed
1
Review items
0
False positives ignored
Audited by: claude

Jul 18, 2026, 12:12 AM

All 18 static findings are false positives caused by Markdown fenced or inline code formatting, not Ruby or shell backtick execution. SKILL.md contains planning guidance and names companion slash commands, but it includes no executable code, credential access, or prompt injection. No security remediation is required.

1
Files scanned
107
Lines analyzed
1
Review items
0
False positives ignored
Audited by: codex

Jul 7, 2026, 08:07 PM

All 18 static external command alerts are false positives from Markdown code fences, inline file names, and documented slash commands. No prompt injection or executable shell instructions were found in SKILL.md. The remaining concern is the documented ClickUp synchronization, which should require explicit user consent before sharing roadmap data.

1
Files scanned
107
Lines analyzed
2
Review items
0
False positives ignored

Confirmed security concerns (1)

Low
External Roadmap Synchronization Requires Consent
The skill describes pushing epics and milestones to ClickUp and pulling status updates. This can share internal roadmap data with a third-party service if implemented without explicit user approval.
The text clearly describes ClickUp synchronization, but the scanned file contains no implementation details. The risk is limited to the stated integration behavior.
Audited by: codex

Jul 6, 2026, 03:33 AM

All static findings are false positives caused by Markdown code fences and inline backticks in SKILL.md. The skill contains planning guidance, file naming conventions, and slash command references, with no evidence of executable shell code, prompt injection, or data exfiltration intent.

1
Files scanned
107
Lines analyzed
1
Review items
0
False positives ignored
Audited by: codex

Jun 28, 2026, 08:57 AM

Static analysis reported external command and weak cryptography patterns, but review found these are false positives in Markdown guidance. The flagged lines contain code fences, inline file names, and slash-command documentation, with no executable scripts, network calls, prompt injection, or secret access found.

1
Files scanned
107
Lines analyzed
0
Review items
2
False positives ignored
Static false positives ignored (2)

These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.

Low
False Positive: Markdown Command References
The external command detections point to a Markdown code fence, inline roadmap file paths, and documented slash commands. These lines describe how a planning skill should organize roadmap files and invoke related commands; they do not execute shell, Ruby, or system commands.
The flagged content is plain Markdown documentation with backticks and slash-command names. No executable code, interpreter directive, subprocess API, or user-controlled command construction appears in the reviewed file.
Low
False Positive: Weak Cryptography Pattern
The high-severity weak cryptography detection points to the YAML description line for roadmap and capacity planning. No hash, cipher, cryptographic API, key handling, or security-sensitive algorithm is present at that location.
Line 3 is descriptive metadata only. The semantic context confirms there is no cryptographic implementation or recommendation to use a weak algorithm.
No confirmed security findings were recorded for this completed audit.
Audited by: codex

Jan 21, 2026, 03:52 PM

This is a documentation-only skill providing strategic planning guidance and methodology. All static findings are false positives from markdown code examples. No executable code, network calls, or file operations detected. Safe for publication.

2
Files scanned
449
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 16, 2026, 04:52 PM

AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.

2
Files scanned
284
Lines analyzed
1
Review items
0
False positives ignored

Detected Patterns

Weak cryptographic algorithmRuby/shell backtick execution
Audited by: claude

Jan 16, 2026, 04:52 PM

AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.

2
Files scanned
284
Lines analyzed
1
Review items
0
False positives ignored

Detected Patterns

Weak cryptographic algorithmRuby/shell backtick execution
Audited by: claude

Jan 10, 2026, 10:19 AM

This is a declarative SKILL.md training document containing only markdown-based expertise guidance. No executable code, scripts, network operations, or filesystem access beyond configuration. Pure prompt-based skill for training AI on strategic planning methodology.

1
Files scanned
107
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 10, 2026, 10:19 AM

This is a declarative SKILL.md training document containing only markdown-based expertise guidance. No executable code, scripts, network operations, or filesystem access beyond configuration. Pure prompt-based skill for training AI on strategic planning methodology.

1
Files scanned
107
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 10, 2026, 10:19 AM

This is a declarative SKILL.md training document containing only markdown-based expertise guidance. No executable code, scripts, network operations, or filesystem access beyond configuration. Pure prompt-based skill for training AI on strategic planning methodology.

1
Files scanned
107
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude