Audit History
designing-tests - 10 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v10 Latest | Jul 9, 2026, 02:22 PM | No confirmed findings | 3 | No capability change |
| v9 | Jul 9, 2026, 02:22 PM | No confirmed findings | 3 | No capability change |
| v8 | Jul 6, 2026, 07:30 AM | No confirmed findings | 3 | No capability change |
| v7 | Jul 6, 2026, 07:30 AM | No confirmed findings | 3 | No capability change |
| v6 | Jun 28, 2026, 11:18 PM | 1 confirmed | 0 | No capability change |
| v5 | Jan 16, 2026, 09:47 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 09:47 PM | No confirmed findings | 0 | Network accessExternal commands |
| v3 | Jan 10, 2026, 12:32 PM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 12:32 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 12:32 PM | No confirmed findings | 0 | Baseline |
Jul 9, 2026, 02:22 PM
Most static findings are false positives caused by Markdown code fences, mock HTTP examples, and ordinary test templates. The skill does instruct agents to run npm test commands, which can execute project-defined scripts and should require user approval in untrusted repositories. No prompt injection or data exfiltration intent was found.
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (23)
🌐 Network access (2)
Jul 9, 2026, 02:22 PM
Most static findings are false positives caused by Markdown code fences, mock HTTP examples, and ordinary test templates. The skill does instruct agents to run npm test commands, which can execute project-defined scripts and should require user approval in untrusted repositories. No prompt injection or data exfiltration intent was found.
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (23)
🌐 Network access (2)
Jul 6, 2026, 07:30 AM
Most static findings are Markdown fences, documentation examples, local test code, or mock handlers. The only confirmed risk is guidance to run npm test commands, because npm scripts can execute repository-defined code. No evidence found of prompt injection, data exfiltration, or malicious intent in SKILL.md.
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (23)
🌐 Network access (2)
Jul 6, 2026, 07:30 AM
Most static findings are Markdown fences, documentation examples, local test code, or mock handlers. The only confirmed risk is guidance to run npm test commands, because npm scripts can execute repository-defined code. No evidence found of prompt injection, data exfiltration, or malicious intent in SKILL.md.
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (23)
🌐 Network access (2)
Jun 28, 2026, 11:18 PM
Static analysis flagged many backticks, weak cryptography keywords, reconnaissance terms, and HTTP patterns. Manual review found Markdown test examples, local test commands, and mock HTTP handlers, with no malicious intent or prompt injection evidence.
Confirmed security concerns (1)
Static false positives ignored (4)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (2)
🌐 Network access (2)
Jan 16, 2026, 09:47 PM
This is a documentation-only skill containing testing guidance and templates. The static analyzer flagged 64 patterns as potentially malicious, but ALL findings are false positives caused by markdown documentation being misinterpreted as code. The skill contains no executable code, network calls, file system operations, or cryptographic implementations. All flagged patterns are legitimate documentation elements: code examples (``` fences), test data patterns, and testing terminology.
Risk Factors
🌐 Network access (2)
⚙️ External commands (23)
Jan 16, 2026, 09:47 PM
This is a documentation-only skill containing testing guidance and templates. The static analyzer flagged 64 patterns as potentially malicious, but ALL findings are false positives caused by markdown documentation being misinterpreted as code. The skill contains no executable code, network calls, file system operations, or cryptographic implementations. All flagged patterns are legitimate documentation elements: code examples (``` fences), test data patterns, and testing terminology.
Risk Factors
🌐 Network access (2)
⚙️ External commands (23)
Jan 10, 2026, 12:32 PM
This is a documentation-only skill that provides testing guidance and templates. It contains no executable code, network calls, or file system access. The skill is purely educational with code examples for test implementation.
Jan 10, 2026, 12:32 PM
This is a documentation-only skill that provides testing guidance and templates. It contains no executable code, network calls, or file system access. The skill is purely educational with code examples for test implementation.
Jan 10, 2026, 12:32 PM
This is a documentation-only skill that provides testing guidance and templates. It contains no executable code, network calls, or file system access. The skill is purely educational with code examples for test implementation.