📦

Audit History

receiving-code-review - 9 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v9 LatestJul 5, 2026, 08:06 AM No confirmed findings0No capability change
v8 Jul 5, 2026, 08:06 AM No confirmed findings0 Network access
v7 Jun 29, 2026, 09:50 AM 2 confirmed2External commandsNetwork access
v6 Jan 21, 2026, 04:52 PM No confirmed findings0 External commands
v5 Jan 17, 2026, 12:02 AM No confirmed findings0No capability change
v4 Jan 17, 2026, 12:02 AM No confirmed findings0External commands
v3 Jan 10, 2026, 12:51 PM No confirmed findings0No capability change
v2 Jan 10, 2026, 12:51 PM No confirmed findings0No capability change
v1 Jan 10, 2026, 12:51 PM No confirmed findings0Baseline

Jul 5, 2026, 08:06 AM

All static external-command findings are false positives caused by Markdown code fences, pseudocode, or inline example text. No executable scripts, network reconnaissance instructions, data exfiltration intent, or prompt injection attempts were found in SKILL.md.

1
Files scanned
214
Lines analyzed
1
Review items
0
False positives ignored
Audited by: codex

Jul 5, 2026, 08:06 AM

All static external-command findings are false positives caused by Markdown code fences, pseudocode, or inline example text. No executable scripts, network reconnaissance instructions, data exfiltration intent, or prompt injection attempts were found in SKILL.md.

1
Files scanned
214
Lines analyzed
1
Review items
0
False positives ignored
Audited by: codex

Jun 29, 2026, 09:50 AM

Static findings for Ruby or shell backtick execution are false positives caused by Markdown fenced examples, not executable code. Static weak cryptography and network reconnaissance findings are also false positives from prose. The skill does include legitimate workflow instructions that may cause repository inspection and GitHub API replies, so publication is acceptable with a medium operational warning.

1
Files scanned
214
Lines analyzed
6
Review items
1
False positives ignored

Confirmed security concerns (2)

Low
Weak Cryptography Pattern Is Prose Only
The static weak cryptography findings occur in natural language examples and metadata. I found no cryptographic algorithm use, hashing API, encryption library, or credential handling in the skill.
The cited lines are descriptive text or example response text. There is no code path where DES, MD5, SHA1, or another weak algorithm is invoked.
Low
Network Reconnaissance Pattern Is Prose Only
The static network reconnaissance finding points to guidance about using technical reasoning when responding to review feedback. I found no scanning, port probing, host enumeration, or reconnaissance command.
The cited line is a plain-language instruction inside review guidance. It contains no network target, tool invocation, or discovery workflow.
Capability review items (2)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Medium
Operational GitHub API Instruction
The skill instructs agents replying to GitHub inline review comments to use the GitHub API reply endpoint. This is a legitimate code review workflow, but it can perform network actions and post content to a repository if the agent has GitHub credentials.
The instruction is explicit and semantically tied to GitHub API use. I found no evidence of exfiltration or malicious endpoints, so the concern is operational rather than malicious.
Medium
Codebase Inspection May Invoke Local Search
The skill tells the assistant to grep the codebase before accepting broad feature work. This is appropriate for code review, but it means the skill may prompt local repository reads or search commands.
The instruction directly names grep and repository inspection. The behavior is limited to verification and does not show command injection or destructive intent.
Static false positives ignored (1)

These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.

Low
Markdown Fences Misidentified as Shell Backticks
The static analyzer flagged many Markdown code fences as Ruby or shell backtick execution. These blocks contain review workflow pseudocode and example dialogue, not executable scripts.
The flagged syntax is Markdown fencing around examples. No shell interpolation, command substitution, or executable Ruby code is present in these locations.

Risk Factors

⚙️ External commands (1)
🌐 Network access (1)

Detected Patterns

External Command ReferenceNetwork-Capable GitHub API Reference
Audited by: codex

Jan 21, 2026, 04:52 PM

This is a pure documentation skill providing guidance on code review feedback handling. All 36 static findings are false positives: C2 keywords are movie quotes, cryptographic patterns are markdown file extensions, backticks are documentation code blocks, and URLs are legitimate GitHub references. No actual code execution or network access.

2
Files scanned
652
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 17, 2026, 12:02 AM

AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.

2
Files scanned
391
Lines analyzed
1
Review items
0
False positives ignored

Detected Patterns

Weak cryptographic algorithmRuby/shell backtick executionNetwork reconnaissance
Audited by: claude

Jan 17, 2026, 12:02 AM

AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.

2
Files scanned
391
Lines analyzed
1
Review items
0
False positives ignored

Detected Patterns

Weak cryptographic algorithmRuby/shell backtick executionNetwork reconnaissance
Audited by: claude

Jan 10, 2026, 12:51 PM

This is a pure prompt-based skill with no code execution, file access, or network capabilities. It provides guidelines for handling code review feedback with technical rigor.

1
Files scanned
214
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 10, 2026, 12:51 PM

This is a pure prompt-based skill with no code execution, file access, or network capabilities. It provides guidelines for handling code review feedback with technical rigor.

1
Files scanned
214
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 10, 2026, 12:51 PM

This is a pure prompt-based skill with no code execution, file access, or network capabilities. It provides guidelines for handling code review feedback with technical rigor.

1
Files scanned
214
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude