Audit History
fixing-motion-performance - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 23, 2026, 06:43 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 8, 2026, 02:22 AM | No confirmed findings | 0 | No capability change |
| v3 | Jul 6, 2026, 02:39 PM | No confirmed findings | 0 | External commands |
| v2 | Jun 30, 2026, 04:20 AM | No confirmed findings | 0 | No capability change |
| v1 | Feb 11, 2026, 08:59 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 06:43 PM
All ten static findings are false positives caused by Markdown backticks, code fences, JavaScript template literals, and ordinary animation guidance. The skill contains no executable scripts, system reconnaissance, prompt injection, or other semantic security concerns.
Risk Factors
⚙️ External commands (6)
Jul 8, 2026, 02:22 AM
I found no evidence of malicious behavior or prompt injection in SKILL.md. All static findings are false positives caused by Markdown command examples, code fences, JavaScript template literals, or ordinary performance guidance.
Risk Factors
⚙️ External commands (6)
Jul 6, 2026, 02:39 PM
The flagged backtick strings are usage examples for invoking the skill, not shell execution. The remaining flagged lines are animation guidance prose and show no reconnaissance, prompt injection, or unsafe behavior.
Risk Factors
⚙️ External commands (2)
Jun 30, 2026, 04:20 AM
The static findings were reviewed against the Markdown content and were all false positives. The file contains guidance for animation performance reviews, with no executable code, network access, credential access, prompt injection, or malicious intent found.
Static false positives ignored (7)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Feb 11, 2026, 08:59 AM
All 7 static findings are false positives. The scanner misidentified slash command documentation as external commands, CSS performance terminology as system reconnaissance, and YAML field names as cryptographic patterns. This is a documentation-only skill containing 128 lines of markdown guidelines for animation performance optimization. No code execution, network calls, file operations, or script execution occurs.