Audit History
MCP Integration - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 19, 2026, 09:39 AM | 5 confirmed | 1 | No capability change |
| v8 | Jul 8, 2026, 01:43 AM | No confirmed findings | 0 | No capability change |
| v7 | Jul 5, 2026, 09:05 AM | No confirmed findings | 0 | Filesystem access |
| v6 | Jun 29, 2026, 01:13 PM | 1 confirmed | 4 | Filesystem access |
| v5 | Jan 17, 2026, 01:55 AM | No confirmed findings | 0 | No capability change |
| v4 | Jan 17, 2026, 01:55 AM | No confirmed findings | 0 | Network accessEnv variablesExternal commands |
| v3 | Jan 7, 2026, 01:23 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 7, 2026, 01:23 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 7, 2026, 01:23 AM | No confirmed findings | 0 | Baseline |
Jul 19, 2026, 09:39 AM
Most static alerts are false positives caused by Markdown fences, placeholders, example URLs, and documented authentication patterns. The audit confirms unsafe `.env` loading guidance that can execute file contents. Additional risks include unpinned package execution, broad filesystem access, unrestricted autonomous tools, and secret-printing troubleshooting.
Confirmed security concerns (5)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (37)
🔑 Env variables (22)
⚙️ External commands (50)
Jul 8, 2026, 01:43 AM
All static findings were adjudicated as documentation or example configuration, not executable behavior. The reviewed files mention URLs, environment variable placeholders, and shell snippets, but no automatic command execution, credential exfiltration, or prompt injection text was found.
Risk Factors
🌐 Network access (37)
🔑 Env variables (22)
⚙️ External commands (84)
Jul 5, 2026, 09:05 AM
The static findings are expected documentation examples for MCP endpoints, environment-variable placeholders, and shell snippets. They do not execute code, include live secrets, or show data-exfiltration intent. No prompt injection attempts or hidden malicious instructions were found in the reviewed files.
Risk Factors
🌐 Network access (37)
🔑 Env variables (22)
⚙️ External commands (84)
Jun 29, 2026, 01:13 PM
Static analysis reported a critical combination of command execution, network access, and credential handling, but review found these patterns in documentation and example MCP configuration, not concealed executable code. The skill is not malicious, but it legitimately teaches users to start local processes, connect to remote MCP endpoints, and pass credentials through environment variables, so publication should include a security warning.
Confirmed security concerns (1)
Capability review items (4)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (4)
📁 Filesystem access (3)
🔑 Env variables (4)
⚙️ External commands (4)
Detected Patterns
Jan 17, 2026, 01:55 AM
This is a documentation-only skill providing guidance for MCP server configuration. Static findings flag command patterns, URLs, and env var placeholders in documentation examples, but these are legitimate configuration examples, not executable code. The skill does not execute any code, make network requests, or access credentials directly.
Risk Factors
🌐 Network access (42)
🔑 Env variables (29)
⚙️ External commands (280)
Jan 17, 2026, 01:55 AM
This is a documentation-only skill providing guidance for MCP server configuration. Static findings flag command patterns, URLs, and env var placeholders in documentation examples, but these are legitimate configuration examples, not executable code. The skill does not execute any code, make network requests, or access credentials directly.
Risk Factors
🌐 Network access (42)
🔑 Env variables (29)
⚙️ External commands (280)
Jan 7, 2026, 01:23 AM
This is a documentation-only skill providing guidance on MCP configuration patterns. Contains no executable code, no file access, no network operations, and no command execution capabilities. All content is markdown documentation and example JSON configurations.
Jan 7, 2026, 01:23 AM
This is a documentation-only skill providing guidance on MCP configuration patterns. Contains no executable code, no file access, no network operations, and no command execution capabilities. All content is markdown documentation and example JSON configurations.
Jan 7, 2026, 01:23 AM
This is a documentation-only skill providing guidance on MCP configuration patterns. Contains no executable code, no file access, no network operations, and no command execution capabilities. All content is markdown documentation and example JSON configurations.