Audit History
code-review-playbook - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 23, 2026, 05:55 AM | No confirmed findings | 0 | No capability change |
| v8 | Jul 8, 2026, 12:00 AM | No confirmed findings | 0 | No capability change |
| v7 | Jul 5, 2026, 02:20 AM | 2 confirmed | 0 | External commandsNetwork access |
| v6 | Jun 28, 2026, 09:42 AM | 2 confirmed | 0 | External commandsNetwork access |
| v5 | Jan 16, 2026, 04:26 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 04:26 PM | No confirmed findings | 0 | External commandsNetwork access |
| v3 | Jan 10, 2026, 10:31 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 10:31 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 10:31 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 05:55 AM
All 64 static findings are false positives caused by prose, Markdown formatting, TypeScript examples, or a documentation link. No prompt injection, command execution, reconnaissance, data exfiltration, or unsafe network behavior was found.
Risk Factors
⚙️ External commands (50)
🌐 Network access (1)
Jul 8, 2026, 12:00 AM
All static findings were adjudicated as false positives after reviewing the cited context. The alerts come from markdown code fences, inline examples, a documentation link, and ordinary review checklist language, with no evidence of shell execution, reconnaissance, exfiltration, or prompt injection.
Risk Factors
⚙️ External commands (57)
🌐 Network access (1)
Jul 5, 2026, 02:20 AM
All 64 static hits are false positives from Markdown examples, inline code, review language, or a documentation link. Semantic findings cover external AI API submission of source code and prompt construction without untrusted-input guardrails.
Confirmed security concerns (2)
Risk Factors
⚙️ External commands (57)
🌐 Network access (1)
Jun 28, 2026, 09:42 AM
Static command, crypto, reconnaissance, and network flags were reviewed as Markdown examples, checklist labels, or documentation links rather than executable behavior. No malicious intent, prompt-injection text, credential exfiltration, or runnable command execution was found. The main concern is that copyable LLM review automation examples interpolate untrusted diffs and code into prompts without prompt-injection guidance.
Confirmed security concerns (2)
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Jan 16, 2026, 04:26 PM
This is a pure prompt-based documentation skill containing only code review checklists, templates, and best practices. No executable code, network calls, file system access beyond reading its own markdown files, or external command execution capabilities. All TypeScript code snippets are embedded examples for illustration purposes only.
Risk Factors
⚙️ External commands (109)
🌐 Network access (2)
Jan 16, 2026, 04:26 PM
This is a pure prompt-based documentation skill containing only code review checklists, templates, and best practices. No executable code, network calls, file system access beyond reading its own markdown files, or external command execution capabilities. All TypeScript code snippets are embedded examples for illustration purposes only.
Risk Factors
⚙️ External commands (109)
🌐 Network access (2)
Jan 10, 2026, 10:31 AM
This is a pure prompt-based documentation skill containing only code review checklists, templates, and best practices. No executable code, network calls, file system access beyond reading its own markdown files, or external command execution capabilities. All TypeScript code snippets are embedded examples for illustration purposes only.
Jan 10, 2026, 10:31 AM
This is a pure prompt-based documentation skill containing only code review checklists, templates, and best practices. No executable code, network calls, file system access beyond reading its own markdown files, or external command execution capabilities. All TypeScript code snippets are embedded examples for illustration purposes only.
Jan 10, 2026, 10:31 AM
This is a pure prompt-based documentation skill containing only code review checklists, templates, and best practices. No executable code, network calls, file system access beyond reading its own markdown files, or external command execution capabilities. All TypeScript code snippets are embedded examples for illustration purposes only.