Skills journey-map Audit History
📦

Audit History

journey-map - 8 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v8 LatestJul 6, 2026, 09:55 AM No confirmed findings0No capability change
v7 Jul 6, 2026, 09:55 AM No confirmed findings0External commands
v6 Jun 29, 2026, 09:11 AM No confirmed findings0 External commands
v5 Jan 17, 2026, 12:54 AM No confirmed findings0No capability change
v4 Jan 17, 2026, 12:54 AM No confirmed findings0External commands
v3 Jan 10, 2026, 01:40 PM No confirmed findings0No capability change
v2 Jan 10, 2026, 01:40 PM No confirmed findings0No capability change
v1 Jan 10, 2026, 01:40 PM No confirmed findings0Baseline

Jul 6, 2026, 09:55 AM

All static command-execution alerts are false positives caused by Markdown code fences and inline backtick text in SKILL.md. The skill contains journey-mapping guidance and does not instruct file, network, environment, or shell access. No prompt-injection or malicious intent evidence was found.

1
Files scanned
115
Lines analyzed
1
Review items
0
False positives ignored
Audited by: codex

Jul 6, 2026, 09:55 AM

All static command-execution alerts are false positives caused by Markdown code fences and inline backtick text in SKILL.md. The skill contains journey-mapping guidance and does not instruct file, network, environment, or shell access. No prompt-injection or malicious intent evidence was found.

1
Files scanned
115
Lines analyzed
1
Review items
0
False positives ignored
Audited by: codex

Jun 29, 2026, 09:11 AM

Static analysis flagged markdown backticks as shell execution and ordinary words as weak cryptographic algorithms. Manual review found only documentation, example formatting, and skill usage guidance, with no executable code, network access, filesystem access, or prompt injection.

1
Files scanned
115
Lines analyzed
0
Review items
2
False positives ignored
Static false positives ignored (2)

These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.

Low
False Positive: Markdown Backticks Detected as Shell Execution
The flagged locations are fenced markdown examples or inline skill names, not Ruby or shell execution. No command invocation or user input execution is present.
The reviewed file is markdown documentation. The detected backticks delimit an emotion chart, output template, and inline references.
Low
False Positive: Weak Cryptographic Algorithm Terms
The flagged lines contain journey mapping prose and table headings. No hashing, encryption, cryptographic API, or security-sensitive algorithm use appears in the file.
The suspicious tokens occur in user experience documentation. There is no code path where cryptographic behavior could execute.
No confirmed security findings were recorded for this completed audit.
Audited by: codex

Jan 17, 2026, 12:54 AM

This skill is a pure documentation file containing journey mapping methodology and guidance. The static analysis findings are false positives caused by a broken pattern matcher. The 'weak cryptographic algorithm' detections are common English words (emotion, action, retention) incorrectly flagged. The 'backtick execution' findings are ASCII art diagrams, not shell commands. The skill contains no executable code, scripts, network calls, filesystem access, or external command execution.

2
Files scanned
296
Lines analyzed
1
Review items
0
False positives ignored
Audited by: claude

Jan 17, 2026, 12:54 AM

This skill is a pure documentation file containing journey mapping methodology and guidance. The static analysis findings are false positives caused by a broken pattern matcher. The 'weak cryptographic algorithm' detections are common English words (emotion, action, retention) incorrectly flagged. The 'backtick execution' findings are ASCII art diagrams, not shell commands. The skill contains no executable code, scripts, network calls, filesystem access, or external command execution.

2
Files scanned
296
Lines analyzed
1
Review items
0
False positives ignored
Audited by: claude

Jan 10, 2026, 01:40 PM

This skill contains only documentation and guidance in markdown format. No executable code, scripts, network calls, filesystem access, or external command execution. Pure prompt-based skill with no security concerns.

1
Files scanned
115
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 10, 2026, 01:40 PM

This skill contains only documentation and guidance in markdown format. No executable code, scripts, network calls, filesystem access, or external command execution. Pure prompt-based skill with no security concerns.

1
Files scanned
115
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 10, 2026, 01:40 PM

This skill contains only documentation and guidance in markdown format. No executable code, scripts, network calls, filesystem access, or external command execution. Pure prompt-based skill with no security concerns.

1
Files scanned
115
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude