Audit History
security - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 6, 2026, 05:14 AM | No confirmed findings | 0 | No capability change |
| v7 | Jul 6, 2026, 05:14 AM | No confirmed findings | 0 | No capability change |
| v6 | Jun 28, 2026, 06:14 PM | 1 confirmed | 0 | No capability change |
| v5 | Jan 16, 2026, 08:48 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 08:48 PM | No confirmed findings | 0 | External commands |
| v3 | Jan 10, 2026, 11:40 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 11:40 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 11:40 AM | No confirmed findings | 0 | Baseline |
Jul 6, 2026, 05:14 AM
The only static finding is a Markdown bash code block listing hardcoded security commands. I found no executable code, prompt injection, credential exfiltration, or malicious intent in SKILL.md.
Risk Factors
⚙️ External commands (1)
Jul 6, 2026, 05:14 AM
The only static finding is a Markdown bash code block listing hardcoded security commands. I found no executable code, prompt injection, credential exfiltration, or malicious intent in SKILL.md.
Risk Factors
⚙️ External commands (1)
Jun 28, 2026, 06:14 PM
Static analysis flagged a command block and two weak-cryptography patterns. The command block is documented guidance for local security tools, while the weak-cryptography matches are false positives in descriptive security text.
Confirmed security concerns (1)
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (1)
Detected Patterns
Jan 16, 2026, 08:48 PM
This is a documentation-only skill containing no executable code. Both SKILL.mdare metadata and documentation files that describe security workflows and list example bash commands as documentation. No file system access, network calls, or code execution capabilities exist. All 12 static findings are FALSE POSITIVES caused by the scanner misidentifying documentation keywords as security vulnerabilities.
Risk Factors
⚙️ External commands (1)
Jan 16, 2026, 08:48 PM
This is a documentation-only skill containing no executable code. Both SKILL.mdare metadata and documentation files that describe security workflows and list example bash commands as documentation. No file system access, network calls, or code execution capabilities exist. All 12 static findings are FALSE POSITIVES caused by the scanner misidentifying documentation keywords as security vulnerabilities.
Risk Factors
⚙️ External commands (1)
Jan 10, 2026, 11:40 AM
This is a documentation-only skill containing no executable code. The SKILL.md file describes security workflows and lists command examples as documentation. It references standard security tools (GPG, SSH, Bandit, pip-audit, Safety, Semgrep) that users run directly. No file system access, network calls, or code execution capabilities are present.
Jan 10, 2026, 11:40 AM
This is a documentation-only skill containing no executable code. The SKILL.md file describes security workflows and lists command examples as documentation. It references standard security tools (GPG, SSH, Bandit, pip-audit, Safety, Semgrep) that users run directly. No file system access, network calls, or code execution capabilities are present.
Jan 10, 2026, 11:40 AM
This is a documentation-only skill containing no executable code. The SKILL.md file describes security workflows and lists command examples as documentation. It references standard security tools (GPG, SSH, Bandit, pip-audit, Safety, Semgrep) that users run directly. No file system access, network calls, or code execution capabilities are present.