Audit History
golang-pro - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Aug 7, 2026, 09:42 AM | No confirmed findings | 0 | No capability change |
| v4 | Jul 6, 2026, 02:49 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 6, 2026, 02:49 PM | No confirmed findings | 0 | No capability change |
| v2 | Jun 30, 2026, 04:03 AM | No confirmed findings | 5 | Contains scriptsExternal commandsNetwork accessFilesystem accessEnv variables |
| v1 | Feb 7, 2026, 08:45 AM | No confirmed findings | 0 | Baseline |
Aug 7, 2026, 09:42 AM
All 64 static detections are false positives caused by Go examples, Markdown formatting, Makefile snippets, configuration tags, or documentation links. No executable scripts, data exfiltration intent, or prompt injection evidence was found in the six scanned files.
Risk Factors
⚡ Contains scripts (9)
🌐 Network access (4)
⚙️ External commands (37)
📁 Filesystem access (2)
🔑 Env variables (1)
Jul 6, 2026, 02:49 PM
All static findings are false positives caused by Go, Makefile, and Markdown examples in reference documentation. I found no prompt injection, credential exfiltration intent, hidden command execution, or malicious network behavior.
Risk Factors
⚡ Contains scripts (9)
🌐 Network access (3)
⚙️ External commands (32)
📁 Filesystem access (2)
🔑 Env variables (1)
Jul 6, 2026, 02:49 PM
All static findings are false positives caused by Go, Makefile, and Markdown examples in reference documentation. I found no prompt injection, credential exfiltration intent, hidden command execution, or malicious network behavior.
Risk Factors
⚡ Contains scripts (9)
🌐 Network access (3)
⚙️ External commands (32)
📁 Filesystem access (2)
🔑 Env variables (1)
Jun 30, 2026, 04:03 AM
Static analysis reported many command, script, network, filesystem, and environment patterns, but review found them inside markdown reference examples. No runnable skill code, prompt injection attempt, credential exfiltration, or hidden malicious behavior was found. The remaining risk is low because users may copy operational command examples into their own projects.
Capability review items (5)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚡ Contains scripts (9)
⚙️ External commands (159)
🌐 Network access (3)
📁 Filesystem access (2)
🔑 Env variables (1)
Feb 7, 2026, 08:45 AM
Documentation skill with legitimate Go programming patterns. All 195 static findings are false positives triggered by code examples in markdown files. No malicious intent detected.
Static false positives ignored (5)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.