Audit History
raffle-winner-picker - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 6, 2026, 07:07 AM | No confirmed findings | 0 | No capability change |
| v6 | Jul 6, 2026, 07:07 AM | No confirmed findings | 0 | External commands |
| v5 | Jun 29, 2026, 01:11 AM | 1 confirmed | 0 | External commands |
| v4 | Jan 16, 2026, 11:00 PM | No confirmed findings | 0 | No capability change |
| v3 | Jan 16, 2026, 11:00 PM | No confirmed findings | 0 | External commands |
| v2 | Jan 6, 2026, 07:48 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 6, 2026, 07:48 AM | No confirmed findings | 0 | Baseline |
Jul 6, 2026, 07:07 AM
All static findings are false positives caused by Markdown fenced examples or benign prose in SKILL.md. I found no evidence of executable code, prompt injection, external command execution, network reconnaissance, or data exfiltration intent.
Risk Factors
Jul 6, 2026, 07:07 AM
All static findings are false positives caused by Markdown fenced examples or benign prose in SKILL.md. I found no evidence of executable code, prompt injection, external command execution, network reconnaissance, or data exfiltration intent.
Risk Factors
Jun 29, 2026, 01:11 AM
Static alerts for Ruby backticks, weak cryptography, and network reconnaissance are false positives after reviewing SKILL.md. The skill contains Markdown instructions only, with no executable code, prompt injection, or malicious intent. The remaining concern is low privacy risk because raffle data may include names, emails, and spreadsheet rows.
Confirmed security concerns (1)
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Jan 16, 2026, 11:00 PM
Static analysis flagged 26 patterns including cryptographic functions and shell commands. Upon evaluation, all findings are false positives. The MD5 usage is for non-security purposes (generating random seeds), shell backticks are example code snippets in documentation, and C2/reconnaissance keywords are normal JSON field names in a skill report file.
Risk Factors
Jan 16, 2026, 11:00 PM
Static analysis flagged 26 patterns including cryptographic functions and shell commands. Upon evaluation, all findings are false positives. The MD5 usage is for non-security purposes (generating random seeds), shell backticks are example code snippets in documentation, and C2/reconnaissance keywords are normal JSON field names in a skill report file.
Risk Factors
Jan 6, 2026, 07:48 AM
This skill contains only documentation with no executable code, network calls, or file system access. It's a pure prompt-based skill with zero security risks.
Jan 6, 2026, 07:48 AM
This skill contains only documentation with no executable code, network calls, or file system access. It's a pure prompt-based skill with zero security risks.