Audit History
skill-from-masters - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 6, 2026, 03:25 PM | No confirmed findings | 0 | No capability change |
| v7 | Jul 6, 2026, 03:25 PM | No confirmed findings | 0 | External commands Network access |
| v6 | Jun 30, 2026, 01:27 AM | 1 confirmed | 1 | Network access External commands |
| v5 | Jan 17, 2026, 05:34 AM | No confirmed findings | 0 | No capability change |
| v4 | Jan 17, 2026, 05:34 AM | No confirmed findings | 0 | External commands |
| v3 | Jan 10, 2026, 05:40 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 05:40 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 05:40 AM | No confirmed findings | 0 | Baseline |
Jul 6, 2026, 03:25 PM
All static findings are false positives caused by Markdown formatting and benign research language. No prompt injection, command execution, data exfiltration, or system reconnaissance intent was found in SKILL.md or references/methodology-database.md.
Risk Factors
⚙️ External commands (1)
Jul 6, 2026, 03:25 PM
All static findings are false positives caused by Markdown formatting and benign research language. No prompt injection, command execution, data exfiltration, or system reconnaissance intent was found in SKILL.md or references/methodology-database.md.
Risk Factors
⚙️ External commands (1)
Jun 30, 2026, 01:27 AM
Static weak cryptography, system reconnaissance, and external command alerts were reviewed as false positives caused by prose, Markdown formatting, and framework names. The only confirmed concern is legitimate web research behavior, which may send user-provided topics to search or browsing tools.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (3)
Jan 17, 2026, 05:34 AM
All 45 static findings are FALSE POSITIVES. The skill is pure documentation with no executable code. Pattern detections (Weak Cryptographic Algorithm, System Reconnaissance, C2 Keywords) are triggered by author names in the methodology database (e.g., Schwartz, Ousterhout) and documentation language about web search. No data exfiltration, code execution, or malicious behavior exists.
Risk Factors
⚙️ External commands (1)
Jan 17, 2026, 05:34 AM
All 45 static findings are FALSE POSITIVES. The skill is pure documentation with no executable code. Pattern detections (Weak Cryptographic Algorithm, System Reconnaissance, C2 Keywords) are triggered by author names in the methodology database (e.g., Schwartz, Ousterhout) and documentation language about web search. No data exfiltration, code execution, or malicious behavior exists.
Risk Factors
⚙️ External commands (1)
Jan 10, 2026, 05:40 AM
This is a pure prompt-based skill with no executable code. It guides users through a methodology discovery process using a local database and web search triggers. No data exfiltration, code execution, network calls, or persistence mechanisms detected.
Jan 10, 2026, 05:40 AM
This is a pure prompt-based skill with no executable code. It guides users through a methodology discovery process using a local database and web search triggers. No data exfiltration, code execution, network calls, or persistence mechanisms detected.
Jan 10, 2026, 05:40 AM
This is a pure prompt-based skill with no executable code. It guides users through a methodology discovery process using a local database and web search triggers. No data exfiltration, code execution, network calls, or persistence mechanisms detected.