Audit History
memory - 13 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v13 Latest | Jul 23, 2026, 12:05 PM | 2 confirmed | 0 | No capability change |
| v12 | Jul 17, 2026, 11:03 AM | No confirmed findings | 0 | No capability change |
| v11 | Jul 17, 2026, 11:03 AM | No confirmed findings | 0 | No capability change |
| v10 | Jul 17, 2026, 11:03 AM | No confirmed findings | 0 | No capability change |
| v9 | Jul 6, 2026, 05:12 AM | No confirmed findings | 0 | No capability change |
| v8 | Jul 9, 2026, 12:47 PM | No confirmed findings | 3 | No capability change |
| v7 | Jul 6, 2026, 05:12 AM | No confirmed findings | 0 | No capability change |
| v6 | Jun 28, 2026, 08:10 PM | No confirmed findings | 1 | No capability change |
| v5 | Jan 16, 2026, 07:55 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 07:55 PM | No confirmed findings | 0 | No capability change |
| v3 | Jan 10, 2026, 12:15 PM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 12:15 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 12:15 PM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 12:05 PM
Most static alerts are false positives caused by inline Markdown, fixed shell substitutions, intentional project paths, and multilingual text. No explicit prompt injection or obfuscated payload was found. Two semantic risks remain: unsanitized memory promotion and unconfirmed replacement of an unparseable Plans.md file.
Confirmed security concerns (2)
Risk Factors
⚙️ External commands (23)
📁 Filesystem access (4)
Jul 17, 2026, 11:03 AM
All 32 static findings are false positives after contextual review. The shell examples perform local file maintenance with quoted paths, while other detections are Markdown formatting, documentation links, or language-entropy heuristics. No prompt injection, data exfiltration, or malicious intent was found.
Risk Factors
⚙️ External commands (23)
📁 Filesystem access (4)
Jul 17, 2026, 11:03 AM
All 32 static findings are false positives after contextual review. The shell examples perform local file maintenance with quoted paths, while other detections are Markdown formatting, documentation links, or language-entropy heuristics. No prompt injection, data exfiltration, or malicious intent was found.
Risk Factors
⚙️ External commands (23)
📁 Filesystem access (4)
Jul 17, 2026, 11:03 AM
All 32 static findings are false positives after contextual review. The shell examples perform local file maintenance with quoted paths, while other detections are Markdown formatting, documentation links, or language-entropy heuristics. No prompt injection, data exfiltration, or malicious intent was found.
Risk Factors
⚙️ External commands (23)
📁 Filesystem access (4)
Jul 6, 2026, 05:12 AM
Review found no prompt injection, exfiltration, or unsafe command execution intent. Static command findings are Markdown examples or task labels, and entropy findings are Japanese Markdown content rather than encoded payloads.
Risk Factors
📁 Filesystem access (1)
⚙️ External commands (18)
Jul 9, 2026, 12:47 PM
Most external-command and obfuscation alerts are false positives caused by markdown examples, Japanese text, and inline tool names. I confirmed filesystem risk where the skill points outside the skill directory into hidden .claude memory and state paths.
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (23)
📁 Filesystem access (4)
Jul 6, 2026, 05:12 AM
Review found no prompt injection, exfiltration, or unsafe command execution intent. Static command findings are Markdown examples or task labels, and entropy findings are Japanese Markdown content rather than encoded payloads.
Risk Factors
📁 Filesystem access (1)
⚙️ External commands (18)
Jun 28, 2026, 08:10 PM
Static command-execution and weak-crypto findings are false positives caused by Markdown examples, inline paths, YAML frontmatter, and Japanese text entropy. No prompt injection, network access, credential access, or obfuscated payload behavior was found. The skill is publishable with low risk because it intentionally edits local workflow files and may use local Bash commands for backups and diffs.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (96)
📁 Filesystem access (1)
Jan 16, 2026, 07:55 PM
Low-risk utility skill for memory management. All static findings are false positives: command patterns are documentation examples in markdown files, 'weak crypto' flags are YAML frontmatter and SHA256 hashes, and 'C2 keywords' are standard git terminology (merge, migrate). The skill operates within its documented tool permissions, accessing only .claude/ directories and using Bash only for backup creation.
Risk Factors
📁 Filesystem access (4)
⚙️ External commands (2)
Jan 16, 2026, 07:55 PM
Low-risk utility skill for memory management. All static findings are false positives: command patterns are documentation examples in markdown files, 'weak crypto' flags are YAML frontmatter and SHA256 hashes, and 'C2 keywords' are standard git terminology (merge, migrate). The skill operates within its documented tool permissions, accessing only .claude/ directories and using Bash only for backup creation.
Risk Factors
📁 Filesystem access (4)
⚙️ External commands (2)
Jan 10, 2026, 12:15 PM
Low-risk utility skill for memory management. All capabilities match stated purpose. Filesystem access is limited to .claude/ directory for memory files. Bash tool is used only for backup file operations. No network calls or environment variable access detected.
Risk Factors
📁 Filesystem access (4)
⚙️ External commands (2)
Jan 10, 2026, 12:15 PM
Low-risk utility skill for memory management. All capabilities match stated purpose. Filesystem access is limited to .claude/ directory for memory files. Bash tool is used only for backup file operations. No network calls or environment variable access detected.
Risk Factors
📁 Filesystem access (4)
⚙️ External commands (2)
Jan 10, 2026, 12:15 PM
Low-risk utility skill for memory management. All capabilities match stated purpose. Filesystem access is limited to .claude/ directory for memory files. Bash tool is used only for backup file operations. No network calls or environment variable access detected.