Skills check-my-vibe Audit History
📦

Audit History

check-my-vibe - 2 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v2 LatestJul 12, 2026, 02:56 AM No confirmed findings2No capability change
v1 Jul 12, 2026, 02:56 AM No confirmed findings2Baseline

Jul 12, 2026, 02:56 AM

The Markdown backticks are inline URL formatting, not shell execution, and the reconnaissance phrases describe scan limits and credential protections. The skill intentionally opens an external HTTPS scanning service and submits a public target URL, creating a limited third-party disclosure risk.

2
Files scanned
50
Lines analyzed
4
Review items
0
False positives ignored
Capability review items (2)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Low
Hardcoded URL
Use Check My Vibe for an authorized, passive review of one public website. Run the real scan at `htt
The skill explicitly directs use of an external HTTPS service for the scan. Submitting a target URL discloses that public target to the service, although this network access is central to the stated function.
Low
Hardcoded URL
3. Open `https://checkmyvibeapp.com/` in the available browser.
The workflow requires opening the external Check My Vibe website and entering the target URL. This is intentional network access with a limited third-party disclosure risk.

Risk Factors

⚙️ External commands (2)
🌐 Network access (2)
Audited by: codex

Jul 12, 2026, 02:56 AM

The Markdown backticks are inline URL formatting, not shell execution, and the reconnaissance phrases describe scan limits and credential protections. The skill intentionally opens an external HTTPS scanning service and submits a public target URL, creating a limited third-party disclosure risk.

2
Files scanned
50
Lines analyzed
4
Review items
0
False positives ignored
Capability review items (2)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Low
Hardcoded URL
Use Check My Vibe for an authorized, passive review of one public website. Run the real scan at `htt
The skill explicitly directs use of an external HTTPS service for the scan. Submitting a target URL discloses that public target to the service, although this network access is central to the stated function.
Low
Hardcoded URL
3. Open `https://checkmyvibeapp.com/` in the available browser.
The workflow requires opening the external Check My Vibe website and entering the target URL. This is intentional network access with a limited third-party disclosure risk.

Risk Factors

⚙️ External commands (2)
🌐 Network access (2)
Audited by: codex