Audit History
gpt-series-reasoning-style - 6 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v6 Latest | Sep 20, 2026, 03:25 AM | No confirmed findings | 0 | No capability change |
| v5 | Sep 18, 2026, 05:39 AM | No confirmed findings | 0 | No capability change |
| v4 | Sep 17, 2026, 08:05 PM | 1 confirmed | 0 | No capability change |
| v3 | Sep 16, 2026, 07:18 PM | No confirmed findings | 0 | No capability change |
| v2 | Sep 12, 2026, 11:20 AM | No confirmed findings | 1 | No capability change |
| v1 | Sep 11, 2026, 09:27 PM | No confirmed findings | 1 | Baseline |
Sep 20, 2026, 03:25 AM
All 91 static findings were adjudicated as false positives because they reference public metadata, documentation, fixed repository paths, or analysis heuristics rather than executed behavior. No prompt-injection text, data-exfiltration intent, or runtime command execution was evidenced in the reviewed files.
Risk Factors
🌐 Network access (12)
📁 Filesystem access (41)
Sep 18, 2026, 05:39 AM
All 65 static findings are false positives based on their cited snippets. They identify documentation examples, installation paths, Markdown syntax, a standard ignore entry, or entropy heuristics rather than executable malicious behavior; no prompt injection or data-exfiltration intent was evidenced.
Risk Factors
⚙️ External commands (14)
🌐 Network access (6)
📁 Filesystem access (26)
Sep 17, 2026, 08:05 PM
58 个静态命中均对应文档中的安装示例、代码围栏、正则字面量或纯文本熵启发式,未发现相应的运行时攻击行为。AGENTS.md 与 SKILL.md 仍包含控制代理加载顺序和执行规则的高风险提示注入式文本,安装前应由宿主策略和用户明确同意进行约束。
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (10)
🌐 Network access (6)
📁 Filesystem access (26)
Sep 16, 2026, 07:18 PM
26 个静态发现均为误报:证据来自文档安装命令、Markdown 反引号、Python 文本匹配和普通文本熵启发式。未发现实际网络通信、危险命令执行、数据外传或提示注入证据。
Risk Factors
🌐 Network access (3)
📁 Filesystem access (4)
⚙️ External commands (5)
Sep 12, 2026, 11:20 AM
Most static alerts are false positives caused by defensive examples, readable Chinese prose, Markdown syntax, SVG paths, and documented installation locations. One high-risk behavior is confirmed: claim-check executes claims-file commands through shell=True, so hostile or insufficiently reviewed input can run arbitrary code. Static review was capped at 400/554 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (13)
⚙️ External commands (50)
📁 Filesystem access (50)
Sep 11, 2026, 09:27 PM
The audit confirms one high-risk issue: scripts/claim-check.py executes commands from an untrusted claims file with shell=True. The other reviewed matches are false positives from documentation, defensive patterns, test harnesses, installer mechanics, or static-site content; the confirmed issue requires remediation before publication. Static review was capped at 400/536 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.