Audit History
gitea - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 5, 2026, 02:56 PM | No confirmed findings | 0 | No capability change |
| v7 | Jul 5, 2026, 02:56 PM | No confirmed findings | 0 | No capability change |
| v6 | Jun 30, 2026, 12:48 AM | No confirmed findings | 2 | No capability change |
| v5 | Jan 17, 2026, 05:17 AM | No confirmed findings | 0 | No capability change |
| v4 | Jan 17, 2026, 05:17 AM | No confirmed findings | 0 | External commands |
| v3 | Jan 10, 2026, 02:32 PM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 02:32 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 02:32 PM | No confirmed findings | 0 | Baseline |
Jul 5, 2026, 02:56 PM
All static findings are Markdown inline code or fenced command examples, not Ruby shell backtick execution. The skill documents expected tea and git commands for Gitea workflows, and no prompt injection, credential exfiltration, or hidden instructions were found in SKILL.md.
Risk Factors
⚙️ External commands (23)
Jul 5, 2026, 02:56 PM
All static findings are Markdown inline code or fenced command examples, not Ruby shell backtick execution. The skill documents expected tea and git commands for Gitea workflows, and no prompt injection, credential exfiltration, or hidden instructions were found in SKILL.md.
Risk Factors
⚙️ External commands (23)
Jun 30, 2026, 12:48 AM
Static analysis flagged many shell-style command examples and several weak-cryptography patterns. The shell findings are legitimate external command guidance for the tea and git CLIs, while the weak-cryptography hits are false positives on documentation text such as description and Desc. No prompt injection or malicious exfiltration behavior was found in SKILL.md.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (6)
Detected Patterns
Jan 17, 2026, 05:17 AM
Pure documentation skill containing only markdown guidance for using the tea CLI tool. No executable code, no network calls, no file system access. Static findings are false positives from scanner misclassifying metadata fields, hash values, and markdown code blocks as security issues.
Risk Factors
⚙️ External commands (26)
Jan 17, 2026, 05:17 AM
Pure documentation skill containing only markdown guidance for using the tea CLI tool. No executable code, no network calls, no file system access. Static findings are false positives from scanner misclassifying metadata fields, hash values, and markdown code blocks as security issues.
Risk Factors
⚙️ External commands (26)
Jan 10, 2026, 02:32 PM
Pure prompt-based documentation skill with no executable code. Contains only markdown guidance for using the tea CLI tool. No network, filesystem, or command execution capabilities.
Jan 10, 2026, 02:32 PM
Pure prompt-based documentation skill with no executable code. Contains only markdown guidance for using the tea CLI tool. No network, filesystem, or command execution capabilities.
Jan 10, 2026, 02:32 PM
Pure prompt-based documentation skill with no executable code. Contains only markdown guidance for using the tea CLI tool. No network, filesystem, or command execution capabilities.