Audit History
quality-reviewer - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 5, 2026, 01:50 AM | 1 confirmed | 0 | No capability change |
| v7 | Jul 5, 2026, 01:50 AM | 1 confirmed | 0 | Filesystem accessNetwork access |
| v6 | Jun 28, 2026, 10:15 AM | 1 confirmed | 1 | Filesystem accessNetwork access |
| v5 | Jan 16, 2026, 04:02 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 04:02 PM | No confirmed findings | 0 | External commands |
| v3 | Jan 10, 2026, 10:22 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 10:22 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 10:22 AM | No confirmed findings | 0 | Baseline |
Jul 5, 2026, 01:50 AM
The static command-execution alerts are false positives from markdown fences, inline code, and a hardcoded read-only ls example. No malware, credential access, or data exfiltration intent was found, but the skill grants overbroad tool access through a wildcard permission.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (7)
Jul 5, 2026, 01:50 AM
The static command-execution alerts are false positives from markdown fences, inline code, and a hardcoded read-only ls example. No malware, credential access, or data exfiltration intent was found, but the skill grants overbroad tool access through a wildcard permission.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (7)
Jun 28, 2026, 10:15 AM
Static external-command and weak-cryptography alerts are mostly false positives from Markdown fences, inline code formatting, and words such as description. The skill is still medium risk because it grants wildcard tool access, asks the agent to inspect project files, and requires web research.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (1)
📁 Filesystem access (1)
🌐 Network access (2)
Detected Patterns
Jan 16, 2026, 04:02 PM
All 20 static findings are FALSE_POSITIVES. The scanner misclassified documentation syntax (markdown code blocks, backticks, URL fields) as executable code patterns. This is a pure prompt-based skill containing only markdown documentation. The 'ls' commands are example instructions, not executed code. No actual cryptographic algorithms, external commands, or network calls exist in this skill file.
Risk Factors
⚙️ External commands (8)
Jan 16, 2026, 04:02 PM
All 20 static findings are FALSE_POSITIVES. The scanner misclassified documentation syntax (markdown code blocks, backticks, URL fields) as executable code patterns. This is a pure prompt-based skill containing only markdown documentation. The 'ls' commands are example instructions, not executed code. No actual cryptographic algorithms, external commands, or network calls exist in this skill file.
Risk Factors
⚙️ External commands (8)
Jan 10, 2026, 10:22 AM
Prompt-based skill containing only markdown documentation for AI code review guidance. No executable code, scripts, or network calls. Operates as a system prompt instructing the AI to perform file reading and web research - appropriate for the stated purpose.
Jan 10, 2026, 10:22 AM
Prompt-based skill containing only markdown documentation for AI code review guidance. No executable code, scripts, or network calls. Operates as a system prompt instructing the AI to perform file reading and web research - appropriate for the stated purpose.
Jan 10, 2026, 10:22 AM
Prompt-based skill containing only markdown documentation for AI code review guidance. No executable code, scripts, or network calls. Operates as a system prompt instructing the AI to perform file reading and web research - appropriate for the stated purpose.