Audit History
test-driven-development - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 9, 2026, 04:23 PM | No confirmed findings | 0 | No capability change |
| v8 | Jul 9, 2026, 04:23 PM | No confirmed findings | 0 | No capability change |
| v7 | Jul 6, 2026, 11:13 AM | 1 confirmed | 0 | No capability change |
| v6 | Jun 29, 2026, 10:54 PM | No confirmed findings | 1 | No capability change |
| v5 | Jan 17, 2026, 05:04 AM | No confirmed findings | 0 | No capability change |
| v4 | Jan 17, 2026, 05:04 AM | No confirmed findings | 0 | External commands |
| v3 | Jan 10, 2026, 01:32 PM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 01:32 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 01:32 PM | No confirmed findings | 0 | Baseline |
Jul 9, 2026, 04:23 PM
Static findings are false positives caused by Markdown fences, inline examples, and safe local npm test commands in SKILL.md. The network-reconnaissance hits are checklist wording about tests passing, and manual review of SKILL.zip found only the reviewed SKILL.md copy.
Risk Factors
⚙️ External commands (27)
Jul 9, 2026, 04:23 PM
Static findings are false positives caused by Markdown fences, inline examples, and safe local npm test commands in SKILL.md. The network-reconnaissance hits are checklist wording about tests passing, and manual review of SKILL.zip found only the reviewed SKILL.md copy.
Risk Factors
⚙️ External commands (27)
Jul 6, 2026, 11:13 AM
Static command findings were false positives from Markdown fences and inline examples, not executable Ruby or shell backtick evaluation. The zip archive contains only the same SKILL.md content, so the binary review finding is resolved. One semantic risk remains: the prose tells agents to delete code without requiring user confirmation.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (27)
Jun 29, 2026, 10:54 PM
AI review found no evidence of malware, data exfiltration, prompt injection, weak cryptography, or network reconnaissance in SKILL.md. Most static findings are false positives from Markdown code fences and example text. The only real risk factor is guidance to run local npm test commands, which is expected for a TDD skill but should remain user-controlled.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (4)
Jan 17, 2026, 05:04 AM
This is a documentation-only skill containing Test-Driven Development guidelines. No executable code, network calls, file system access, or external commands. Pure educational content. All 53 static findings are false positives from the scanner misinterpreting markdown code block delimiters and JSON metadata as executable code.
Risk Factors
⚙️ External commands (27)
Jan 17, 2026, 05:04 AM
This is a documentation-only skill containing Test-Driven Development guidelines. No executable code, network calls, file system access, or external commands. Pure educational content. All 53 static findings are false positives from the scanner misinterpreting markdown code block delimiters and JSON metadata as executable code.
Risk Factors
⚙️ External commands (27)
Jan 10, 2026, 01:32 PM
This is a documentation-only skill containing Test-Driven Development guidelines. No executable code, network calls, file system access, or external commands. Pure educational content.
Jan 10, 2026, 01:32 PM
This is a documentation-only skill containing Test-Driven Development guidelines. No executable code, network calls, file system access, or external commands. Pure educational content.
Jan 10, 2026, 01:32 PM
This is a documentation-only skill containing Test-Driven Development guidelines. No executable code, network calls, file system access, or external commands. Pure educational content.