Audit History
journey-map - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 6, 2026, 09:55 AM | No confirmed findings | 0 | No capability change |
| v7 | Jul 6, 2026, 09:55 AM | No confirmed findings | 0 | External commands |
| v6 | Jun 29, 2026, 09:11 AM | No confirmed findings | 0 | External commands |
| v5 | Jan 17, 2026, 12:54 AM | No confirmed findings | 0 | No capability change |
| v4 | Jan 17, 2026, 12:54 AM | No confirmed findings | 0 | External commands |
| v3 | Jan 10, 2026, 01:40 PM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 01:40 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 01:40 PM | No confirmed findings | 0 | Baseline |
Jul 6, 2026, 09:55 AM
All static command-execution alerts are false positives caused by Markdown code fences and inline backtick text in SKILL.md. The skill contains journey-mapping guidance and does not instruct file, network, environment, or shell access. No prompt-injection or malicious intent evidence was found.
Risk Factors
⚙️ External commands (5)
Jul 6, 2026, 09:55 AM
All static command-execution alerts are false positives caused by Markdown code fences and inline backtick text in SKILL.md. The skill contains journey-mapping guidance and does not instruct file, network, environment, or shell access. No prompt-injection or malicious intent evidence was found.
Risk Factors
⚙️ External commands (5)
Jun 29, 2026, 09:11 AM
Static analysis flagged markdown backticks as shell execution and ordinary words as weak cryptographic algorithms. Manual review found only documentation, example formatting, and skill usage guidance, with no executable code, network access, filesystem access, or prompt injection.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Jan 17, 2026, 12:54 AM
This skill is a pure documentation file containing journey mapping methodology and guidance. The static analysis findings are false positives caused by a broken pattern matcher. The 'weak cryptographic algorithm' detections are common English words (emotion, action, retention) incorrectly flagged. The 'backtick execution' findings are ASCII art diagrams, not shell commands. The skill contains no executable code, scripts, network calls, filesystem access, or external command execution.
Risk Factors
⚙️ External commands (5)
Jan 17, 2026, 12:54 AM
This skill is a pure documentation file containing journey mapping methodology and guidance. The static analysis findings are false positives caused by a broken pattern matcher. The 'weak cryptographic algorithm' detections are common English words (emotion, action, retention) incorrectly flagged. The 'backtick execution' findings are ASCII art diagrams, not shell commands. The skill contains no executable code, scripts, network calls, filesystem access, or external command execution.
Risk Factors
⚙️ External commands (5)
Jan 10, 2026, 01:40 PM
This skill contains only documentation and guidance in markdown format. No executable code, scripts, network calls, filesystem access, or external command execution. Pure prompt-based skill with no security concerns.
Jan 10, 2026, 01:40 PM
This skill contains only documentation and guidance in markdown format. No executable code, scripts, network calls, filesystem access, or external command execution. Pure prompt-based skill with no security concerns.
Jan 10, 2026, 01:40 PM
This skill contains only documentation and guidance in markdown format. No executable code, scripts, network calls, filesystem access, or external command execution. Pure prompt-based skill with no security concerns.