Audit History
bigquery - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 23, 2026, 11:42 AM | 2 confirmed | 2 | No capability change |
| v8 | Jul 7, 2026, 07:02 PM | 3 confirmed | 0 | No capability change |
| v7 | Jul 6, 2026, 05:48 AM | 2 confirmed | 2 | No capability change |
| v6 | Jun 28, 2026, 03:01 PM | 3 confirmed | 0 | No capability change |
| v5 | Jan 16, 2026, 07:26 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 07:26 PM | No confirmed findings | 0 | External commandsFilesystem access |
| v3 | Jan 10, 2026, 11:25 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 11:25 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 11:25 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 11:42 AM
All 81 Ruby or shell backtick alerts are false positives caused by Markdown and BigQuery identifier syntax, and both reconnaissance alerts are benign guidance. Two fixed /tmp writes remain confirmed, while semantic review found overbroad metadata authorization and disclosure of organization-specific cloud identifiers.
Confirmed security concerns (2)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (50)
📁 Filesystem access (2)
Jul 7, 2026, 07:02 PM
The static Ruby backtick and temp-file findings are false positives caused by Markdown examples, SQL backticks, and documented bq commands. Semantic review found high-risk organization-specific BigQuery guidance that names Monzo projects and includes workflows for sampling or exporting data. No prompt injection text or covert malware behavior was found.
Confirmed security concerns (3)
Risk Factors
⚙️ External commands (81)
📁 Filesystem access (2)
Jul 6, 2026, 05:48 AM
Most static command findings are false positives caused by Markdown or SQL backticks, not Ruby shell execution. Two temp-file writes are real medium-risk examples, and semantic review found high-risk organization-specific BigQuery access guidance involving named sensitive projects.
Confirmed security concerns (2)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (81)
📁 Filesystem access (2)
Jun 28, 2026, 03:01 PM
Manual review found that the static Ruby backtick, weak-crypto, and reconnaissance alerts are mostly false positives caused by Markdown code examples and prose. The confirmed risk is contextual: the skill gives target-specific BigQuery project, dataset, PII, and export guidance that should not be published broadly without sanitization and authorization controls.
Confirmed security concerns (3)
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (5)
📁 Filesystem access (2)
Detected Patterns
Jan 16, 2026, 07:26 PM
Pure documentation skill containing only Markdown guidance for BigQuery CLI usage. All detected patterns are false positives: bash command examples in documentation, repository URLs in metadata, and file paths in safe query patterns. The skill explicitly promotes safe data practices including INFORMATION_SCHEMA queries and data sensitivity guidelines.
Risk Factors
⚙️ External commands (83)
📁 Filesystem access (2)
Jan 16, 2026, 07:26 PM
Pure documentation skill containing only Markdown guidance for BigQuery CLI usage. All detected patterns are false positives: bash command examples in documentation, repository URLs in metadata, and file paths in safe query patterns. The skill explicitly promotes safe data practices including INFORMATION_SCHEMA queries and data sensitivity guidelines.
Risk Factors
⚙️ External commands (83)
📁 Filesystem access (2)
Jan 10, 2026, 11:25 AM
Pure documentation skill containing only Markdown guidance. No executable code, scripts, network calls, or file system access. Promotes safe data practices with explicit warnings about sensitive data handling.
Jan 10, 2026, 11:25 AM
Pure documentation skill containing only Markdown guidance. No executable code, scripts, network calls, or file system access. Promotes safe data practices with explicit warnings about sensitive data handling.
Jan 10, 2026, 11:25 AM
Pure documentation skill containing only Markdown guidance. No executable code, scripts, network calls, or file system access. Promotes safe data practices with explicit warnings about sensitive data handling.