Audit History
parallel-agents - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 21, 2026, 07:38 AM | No confirmed findings | 0 | No capability change |
| v7 | Jul 6, 2026, 11:41 AM | No confirmed findings | 0 | External commands |
| v6 | Jun 29, 2026, 06:56 PM | 1 confirmed | 0 | External commands |
| v5 | Jan 17, 2026, 03:51 AM | No confirmed findings | 0 | No capability change |
| v4 | Jan 17, 2026, 03:51 AM | No confirmed findings | 0 | External commands |
| v3 | Jan 10, 2026, 01:14 PM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 01:14 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 01:14 PM | No confirmed findings | 0 | Baseline |
Jul 21, 2026, 07:38 AM
All 20 static findings are false positives. The scanner treated Markdown backticks and ordinary task-management prose as shell execution or system reconnaissance. The skill documents concurrent agent coordination and contains no executable code, data exfiltration intent, prompt injection, or reconnaissance behavior.
Risk Factors
Jul 6, 2026, 11:41 AM
The static findings are false positives caused by markdown code fences, Task examples, and sample test text. No prompt injection, data exfiltration intent, shell execution, or system reconnaissance behavior was found in SKILL.md.
Risk Factors
Jun 29, 2026, 06:56 PM
Static analysis flagged markdown fences, task examples, and ordinary words as Ruby shell execution, weak cryptography, and reconnaissance patterns. Review found no executable scripts, network calls, credential access, prompt injection, or malicious intent in SKILL.md. The remaining risk is operational: parallel agent delegation can broaden changes if tasks are scoped poorly.
Confirmed security concerns (1)
Jan 17, 2026, 03:51 AM
Documentation-only skill containing markdown guidance on parallel agent execution. No executable code, network calls, or file operations exist. All 35 static findings are false positives: 16 triggered by hash identifiers (SHA-256 content hashes misidentified as weak crypto), 17 by markdown code fences (Task tool syntax examples misidentified as shell backtick execution), and 2 by benign metadata fields. The skill provides best practices for coordinating multiple Claude agents to solve independent problems simultaneously.
Risk Factors
Jan 17, 2026, 03:51 AM
Documentation-only skill containing markdown guidance on parallel agent execution. No executable code, network calls, or file operations exist. All 35 static findings are false positives: 16 triggered by hash identifiers (SHA-256 content hashes misidentified as weak crypto), 17 by markdown code fences (Task tool syntax examples misidentified as shell backtick execution), and 2 by benign metadata fields. The skill provides best practices for coordinating multiple Claude agents to solve independent problems simultaneously.
Risk Factors
Jan 10, 2026, 01:14 PM
This is a documentation-only skill that provides guidance on using Claude's parallel agent capabilities. It contains no executable code, network calls, or file operations - only markdown documentation with best practices and examples.
Jan 10, 2026, 01:14 PM
This is a documentation-only skill that provides guidance on using Claude's parallel agent capabilities. It contains no executable code, network calls, or file operations - only markdown documentation with best practices and examples.
Jan 10, 2026, 01:14 PM
This is a documentation-only skill that provides guidance on using Claude's parallel agent capabilities. It contains no executable code, network calls, or file operations - only markdown documentation with best practices and examples.