Audit History
github-elements-tracking - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 5, 2026, 04:05 PM | 3 confirmed | 81 | No capability change |
| v8 | Jul 5, 2026, 04:05 PM | 3 confirmed | 81 | No capability change |
| v7 | Jun 29, 2026, 11:08 PM | 2 confirmed | 0 | External commandsEnv variablesNetwork access Contains scripts |
| v6 | Jan 23, 2026, 02:30 AM | No confirmed findings | 0 | Contains scripts External commandsNetwork access |
| v5 | Jan 17, 2026, 05:02 AM | No confirmed findings | 0 | No capability change |
| v4 | Jan 17, 2026, 05:02 AM | No confirmed findings | 0 | External commandsFilesystem accessNetwork access |
| v3 | Jan 10, 2026, 02:56 PM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 02:56 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 02:56 PM | No confirmed findings | 0 | Baseline |
Jul 5, 2026, 04:05 PM
Most static hits are documentation artifacts, especially Markdown code spans, example links, and workflow prose. Confirmed risks remain because the skill directs agents to run shell and GitHub CLI commands, write parent worktree paths, modify hidden Claude configuration, install an external MCP package, and install GitHub automation with write permissions.
Confirmed security concerns (3)
Capability review items (81)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (442)
📁 Filesystem access (59)
🔑 Env variables (14)
🌐 Network access (4)
Jul 5, 2026, 04:05 PM
Most static hits are documentation artifacts, especially Markdown code spans, example links, and workflow prose. Confirmed risks remain because the skill directs agents to run shell and GitHub CLI commands, write parent worktree paths, modify hidden Claude configuration, install an external MCP package, and install GitHub automation with write permissions.
Confirmed security concerns (3)
Capability review items (81)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (442)
📁 Filesystem access (59)
🔑 Env variables (14)
🌐 Network access (4)
Jun 29, 2026, 11:08 PM
Static analysis found many command, filesystem, environment, and network patterns, but contextual review shows this package is Markdown workflow documentation rather than executable hidden code. The main confirmed risk is that the playbooks instruct agents to run GitHub CLI, git, shell, workflow, and external tool setup commands, so publication is acceptable with an operational safety warning.
Confirmed security concerns (2)
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (3)
📁 Filesystem access (3)
🔑 Env variables (2)
Detected Patterns
Jan 23, 2026, 02:30 AM
This skill contains documentation and agent playbooks only. Static findings are false positives triggered by documentation examples of shell commands and git operations. No executable code with security implications. The skill provides workflow guidance for using GitHub Issues as persistent memory.
Risk Factors
⚡ Contains scripts (1)
📁 Filesystem access (1)
Jan 17, 2026, 05:02 AM
Documentation-only skill containing markdown files with workflow protocols. All static findings (1338 potential issues) are FALSE POSITIVES. Shell commands and git/gh CLI examples appear in markdown documentation blocks, not executable code. The skill is a pure protocol framework for GitHub-based persistent memory with no malicious patterns.
Risk Factors
⚙️ External commands (2)
📁 Filesystem access (2)
🌐 Network access (2)
Jan 17, 2026, 05:02 AM
Documentation-only skill containing markdown files with workflow protocols. All static findings (1338 potential issues) are FALSE POSITIVES. Shell commands and git/gh CLI examples appear in markdown documentation blocks, not executable code. The skill is a pure protocol framework for GitHub-based persistent memory with no malicious patterns.
Risk Factors
⚙️ External commands (2)
📁 Filesystem access (2)
🌐 Network access (2)
Jan 10, 2026, 02:56 PM
Pure documentation skill with no executable code. Contains markdown files with workflow protocols and bash command examples using gh CLI for GitHub operations. No scripts, no network calls, no file system access beyond project directory.
Jan 10, 2026, 02:56 PM
Pure documentation skill with no executable code. Contains markdown files with workflow protocols and bash command examples using gh CLI for GitHub operations. No scripts, no network calls, no file system access beyond project directory.
Jan 10, 2026, 02:56 PM
Pure documentation skill with no executable code. Contains markdown files with workflow protocols and bash command examples using gh CLI for GitHub operations. No scripts, no network calls, no file system access beyond project directory.