Audit History
copilot-flow - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 5, 2026, 03:44 AM | No confirmed findings | 0 | No capability change |
| v8 | Jul 5, 2026, 03:44 AM | No confirmed findings | 0 | External commands Network accessFilesystem access |
| v7 | Jun 28, 2026, 12:49 PM | 2 confirmed | 0 | Network access |
| v6 | Jan 21, 2026, 04:57 PM | No confirmed findings | 0 | Filesystem access External commands |
| v5 | Jan 16, 2026, 06:21 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 06:21 PM | No confirmed findings | 0 | External commands |
| v3 | Jan 10, 2026, 10:48 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 10:48 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 10:48 AM | No confirmed findings | 0 | Baseline |
Jul 5, 2026, 03:44 AM
All 17 static findings are false positives caused by Markdown backticks, fenced prompt examples, and local file path references. The reviewed SKILL.md describes a staged Claude and Copilot development workflow and does not contain executable code, shell commands, network scanning, or prompt injection. No remediation is required for the reported static findings.
Risk Factors
Jul 5, 2026, 03:44 AM
All 17 static findings are false positives caused by Markdown backticks, fenced prompt examples, and local file path references. The reviewed SKILL.md describes a staged Claude and Copilot development workflow and does not contain executable code, shell commands, network scanning, or prompt injection. No remediation is required for the reported static findings.
Risk Factors
Jun 28, 2026, 12:49 PM
Static analysis reported many high-risk patterns, but the reviewed file contains Markdown documentation rather than executable code. The backtick, weak cryptography, and reconnaissance detections are false positives; the real concerns are repository file modification, external Copilot MCP collaboration, and possible interaction history retention.
Confirmed security concerns (2)
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (4)
📁 Filesystem access (5)
Jan 21, 2026, 04:57 PM
All static findings are false positives. The skill is a legitimate AI collaboration workflow orchestrator that coordinates development tasks between Claude and Copilot. Static scanner detected patterns in metadata fields (hash values, URLs) and documentation file references that do not represent security risks.
Risk Factors
📁 Filesystem access (1)
Jan 16, 2026, 06:21 PM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
Detected Patterns
Jan 16, 2026, 06:21 PM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
Detected Patterns
Jan 10, 2026, 10:48 AM
This is a pure prompt-based skill configuration file. No executable code, scripts, network operations, or command execution paths are present. The skill defines a 5-stage workflow orchestration that delegates actual execution to Claude's native capabilities and the copilot-mcp-server integration.
Jan 10, 2026, 10:48 AM
This is a pure prompt-based skill configuration file. No executable code, scripts, network operations, or command execution paths are present. The skill defines a 5-stage workflow orchestration that delegates actual execution to Claude's native capabilities and the copilot-mcp-server integration.
Jan 10, 2026, 10:48 AM
This is a pure prompt-based skill configuration file. No executable code, scripts, network operations, or command execution paths are present. The skill defines a 5-stage workflow orchestration that delegates actual execution to Claude's native capabilities and the copilot-mcp-server integration.