Audit History
context-save - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 5, 2026, 06:50 AM | 1 confirmed | 0 | No capability change |
| v7 | Jul 5, 2026, 06:50 AM | 1 confirmed | 0 | External commands Filesystem access |
| v6 | Jun 28, 2026, 10:02 PM | No confirmed findings | 1 | Filesystem access External commands |
| v5 | Jan 16, 2026, 08:31 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 08:31 PM | No confirmed findings | 0 | External commands |
| v3 | Jan 10, 2026, 12:13 PM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 12:13 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 12:13 PM | No confirmed findings | 0 | Baseline |
Jul 5, 2026, 06:50 AM
Static external-command, system-reconnaissance, and obfuscation alerts are false positives from Markdown formatting, examples, and readable Chinese prose. No executable shell, Ruby, network, or reconnaissance behavior was found in SKILL.md. A medium-risk issue remains because session notes may persist sensitive context without redaction guidance.
Confirmed security concerns (1)
Risk Factors
Jul 5, 2026, 06:50 AM
Static external-command, system-reconnaissance, and obfuscation alerts are false positives from Markdown formatting, examples, and readable Chinese prose. No executable shell, Ruby, network, or reconnaissance behavior was found in SKILL.md. A medium-risk issue remains because session notes may persist sensitive context without redaction guidance.
Confirmed security concerns (1)
Risk Factors
Jun 28, 2026, 10:02 PM
Static command-execution, weak-crypto, reconnaissance, and entropy findings are false positives caused by Markdown backticks, readable Chinese prose, and example text. The confirmed risk is that the skill directs agents to persist session summaries into repository files, which can accidentally retain secrets or proprietary context.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (4)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
📁 Filesystem access (3)
Jan 16, 2026, 08:31 PM
This is a prompt-based skill with no executable code. SKILL.md contains only natural language instructions for generating markdown session summaries. No file system access, network calls, or command execution capabilities exist in the skill itself. The static analyzer produced false positives by misinterpreting Chinese text and markdown formatting as security vulnerabilities. All findings are dismissed as false positives.
Risk Factors
Jan 16, 2026, 08:31 PM
This is a prompt-based skill with no executable code. SKILL.md contains only natural language instructions for generating markdown session summaries. No file system access, network calls, or command execution capabilities exist in the skill itself. The static analyzer produced false positives by misinterpreting Chinese text and markdown formatting as security vulnerabilities. All findings are dismissed as false positives.
Risk Factors
Jan 10, 2026, 12:13 PM
This is a prompt-based skill with no executable code. It provides instructions for generating markdown session summaries. No file system access, network calls, or command execution capabilities detected. The behavior matches the stated purpose exactly.
Jan 10, 2026, 12:13 PM
This is a prompt-based skill with no executable code. It provides instructions for generating markdown session summaries. No file system access, network calls, or command execution capabilities detected. The behavior matches the stated purpose exactly.
Jan 10, 2026, 12:13 PM
This is a prompt-based skill with no executable code. It provides instructions for generating markdown session summaries. No file system access, network calls, or command execution capabilities detected. The behavior matches the stated purpose exactly.