Audit History
Command Development - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 19, 2026, 03:42 AM | 1 confirmed | 41 | No capability change |
| v8 | Jul 8, 2026, 12:43 AM | No confirmed findings | 0 | No capability change |
| v7 | Jul 6, 2026, 07:55 AM | 2 confirmed | 0 | No capability change |
| v6 | Jun 29, 2026, 01:29 AM | No confirmed findings | 0 | No capability change |
| v5 | Jan 16, 2026, 10:12 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 10:12 PM | No confirmed findings | 0 | External commandsFilesystem accessNetwork access |
| v3 | Jan 9, 2026, 02:55 PM | No confirmed findings | 0 | No capability change |
| v2 | Jan 9, 2026, 02:55 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 9, 2026, 02:55 PM | No confirmed findings | 0 | Baseline |
Jul 19, 2026, 03:42 AM
Most static detections are Markdown formatting, expected Claude paths, test syntax, or documentation links. Multiple executable templates directly interpolate positional arguments into shell text, creating command-injection risk. Predictable temporary files and repeated Bash(*) grants add avoidable exposure, but no prompt injection or covert exfiltration intent was found. Static review was capped at 400/429 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
Confirmed security concerns (1)
Capability review items (41)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (50)
📁 Filesystem access (29)
🌐 Network access (8)
Jul 8, 2026, 12:43 AM
The static findings are Markdown examples for Claude Code slash command syntax, not runnable install or auto-execution logic. No prompt injection, data exfiltration, or malicious intent was found in the reviewed files.
Risk Factors
⚙️ External commands (348)
📁 Filesystem access (29)
🌐 Network access (8)
Jul 6, 2026, 07:55 AM
The static findings are predominantly false positives from Markdown documentation and slash command examples, not executable skill code. No prompt injection attempt, credential exfiltration, or install-time execution behavior was found. The main residual risk is instructional: some examples show broad Bash permissions and direct shell interpolation of user arguments.
Confirmed security concerns (2)
Risk Factors
⚙️ External commands (348)
📁 Filesystem access (29)
🌐 Network access (8)
Jun 29, 2026, 01:29 AM
This official Anthropic skill contains documentation and examples for building Claude Code slash commands. Static indicators reference bash context, file references, and network examples in documentation. No malicious behavior or prompt injection attempts were confirmed.
Risk Factors
⚙️ External commands (946)
📁 Filesystem access (31)
🌐 Network access (8)
Jan 16, 2026, 10:12 PM
Official Anthropic documentation skill containing only markdown teaching content and command examples. No executable code, network operations, or filesystem modifications. Contains comprehensive guidance on slash command development patterns for Claude Code.
Risk Factors
⚙️ External commands (946)
📁 Filesystem access (31)
🌐 Network access (8)
Jan 16, 2026, 10:12 PM
Official Anthropic documentation skill containing only markdown teaching content and command examples. No executable code, network operations, or filesystem modifications. Contains comprehensive guidance on slash command development patterns for Claude Code.
Risk Factors
⚙️ External commands (946)
📁 Filesystem access (31)
🌐 Network access (8)
Jan 9, 2026, 02:55 PM
Official Anthropic skill containing only documentation and markdown examples. No executable code, network operations, or filesystem modifications. Contains teaching content about command development patterns.
Jan 9, 2026, 02:55 PM
Official Anthropic skill containing only documentation and markdown examples. No executable code, network operations, or filesystem modifications. Contains teaching content about command development patterns.
Jan 9, 2026, 02:55 PM
Official Anthropic skill containing only documentation and markdown examples. No executable code, network operations, or filesystem modifications. Contains teaching content about command development patterns.