Audit History
type-safety-validation - 10 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v10 Latest | Jul 23, 2026, 07:06 AM | 1 confirmed | 0 | No capability change |
| v9 | Jul 7, 2026, 06:35 PM | No confirmed findings | 0 | No capability change |
| v8 | Jul 6, 2026, 03:06 AM | No confirmed findings | 0 | No capability change |
| v7 | Jun 28, 2026, 10:43 AM | 1 confirmed | 1 | External commandsNetwork accessFilesystem access |
| v6 | Jan 21, 2026, 04:17 PM | No confirmed findings | 0 | Network accessExternal commandsFilesystem access |
| v5 | Jan 16, 2026, 05:16 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 05:16 PM | No confirmed findings | 0 | Network accessExternal commandsFilesystem access |
| v3 | Jan 10, 2026, 10:54 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 10:54 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 10:54 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 07:06 AM
All 36 static findings are false positives caused by Markdown syntax, TypeScript examples, sample URLs, relative imports, validation chains, and ordinary identifiers. One medium semantic issue remains: the examples expose database reads and writes without authentication or authorization.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (22)
🌐 Network access (6)
📁 Filesystem access (3)
Jul 7, 2026, 06:35 PM
The static findings are false positives caused by Markdown code fences, inline code formatting, example URLs, regex validation examples, and TypeScript import syntax. No prompt injection, data exfiltration intent, command execution path, or real filesystem abuse was found in SKILL.md.
Risk Factors
⚙️ External commands (22)
🌐 Network access (6)
📁 Filesystem access (3)
Jul 6, 2026, 03:06 AM
The static findings are false positives caused by Markdown code fences, inline Markdown, sample URLs, regexes, and normal TypeScript imports. No prompt injection, exfiltration intent, command execution, or unsafe filesystem behavior was found in SKILL.md.
Risk Factors
⚙️ External commands (22)
🌐 Network access (6)
📁 Filesystem access (3)
Jun 28, 2026, 10:43 AM
The static analyzer flagged many high-risk patterns, but review shows they are markdown code fences, TypeScript examples, documentation URLs, and relative imports. No malicious behavior or prompt injection was found. One low-risk documentation issue remains because a sample tRPC mutation uses publicProcedure without showing authentication.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (25)
🌐 Network access (6)
📁 Filesystem access (3)
Detected Patterns
Jan 21, 2026, 04:17 PM
Educational skill providing TypeScript type safety patterns and examples. All 61 static findings are false positives from pattern matching in documentation and code examples. No actual security risks detected.
Jan 16, 2026, 05:16 PM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
🌐 Network access (6)
⚙️ External commands (25)
📁 Filesystem access (3)
Detected Patterns
Jan 16, 2026, 05:16 PM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
🌐 Network access (6)
⚙️ External commands (25)
📁 Filesystem access (3)
Detected Patterns
Jan 10, 2026, 10:54 AM
Pure documentation skill containing only educational content about type safety patterns. No executable code, no network operations, no file access, no external command execution. Risk factor evidence array is empty due to zero detected risk factors.
Jan 10, 2026, 10:54 AM
Pure documentation skill containing only educational content about type safety patterns. No executable code, no network operations, no file access, no external command execution. Risk factor evidence array is empty due to zero detected risk factors.
Jan 10, 2026, 10:54 AM
Pure documentation skill containing only educational content about type safety patterns. No executable code, no network operations, no file access, no external command execution. Risk factor evidence array is empty due to zero detected risk factors.