Audit History
receiving-code-review - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 5, 2026, 08:06 AM | No confirmed findings | 0 | No capability change |
| v8 | Jul 5, 2026, 08:06 AM | No confirmed findings | 0 | Network access |
| v7 | Jun 29, 2026, 09:50 AM | 2 confirmed | 2 | External commandsNetwork access |
| v6 | Jan 21, 2026, 04:52 PM | No confirmed findings | 0 | External commands |
| v5 | Jan 17, 2026, 12:02 AM | No confirmed findings | 0 | No capability change |
| v4 | Jan 17, 2026, 12:02 AM | No confirmed findings | 0 | External commands |
| v3 | Jan 10, 2026, 12:51 PM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 12:51 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 12:51 PM | No confirmed findings | 0 | Baseline |
Jul 5, 2026, 08:06 AM
All static external-command findings are false positives caused by Markdown code fences, pseudocode, or inline example text. No executable scripts, network reconnaissance instructions, data exfiltration intent, or prompt injection attempts were found in SKILL.md.
Risk Factors
⚙️ External commands (24)
Jul 5, 2026, 08:06 AM
All static external-command findings are false positives caused by Markdown code fences, pseudocode, or inline example text. No executable scripts, network reconnaissance instructions, data exfiltration intent, or prompt injection attempts were found in SKILL.md.
Risk Factors
⚙️ External commands (24)
Jun 29, 2026, 09:50 AM
Static findings for Ruby or shell backtick execution are false positives caused by Markdown fenced examples, not executable code. Static weak cryptography and network reconnaissance findings are also false positives from prose. The skill does include legitimate workflow instructions that may cause repository inspection and GitHub API replies, so publication is acceptable with a medium operational warning.
Confirmed security concerns (2)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (1)
🌐 Network access (1)
Detected Patterns
Jan 21, 2026, 04:52 PM
This is a pure documentation skill providing guidance on code review feedback handling. All 36 static findings are false positives: C2 keywords are movie quotes, cryptographic patterns are markdown file extensions, backticks are documentation code blocks, and URLs are legitimate GitHub references. No actual code execution or network access.
Jan 17, 2026, 12:02 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
⚙️ External commands (24)
Detected Patterns
Jan 17, 2026, 12:02 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
⚙️ External commands (24)
Detected Patterns
Jan 10, 2026, 12:51 PM
This is a pure prompt-based skill with no code execution, file access, or network capabilities. It provides guidelines for handling code review feedback with technical rigor.
Jan 10, 2026, 12:51 PM
This is a pure prompt-based skill with no code execution, file access, or network capabilities. It provides guidelines for handling code review feedback with technical rigor.
Jan 10, 2026, 12:51 PM
This is a pure prompt-based skill with no code execution, file access, or network capabilities. It provides guidelines for handling code review feedback with technical rigor.