Audit History
changelog - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Aug 7, 2026, 09:58 AM | No confirmed findings | 0 | No capability change |
| v8 | Jul 23, 2026, 06:45 PM | 1 confirmed | 0 | No capability change |
| v7 | Jul 8, 2026, 02:25 AM | 1 confirmed | 0 | No capability change |
| v6 | Jul 5, 2026, 06:43 PM | No confirmed findings | 0 | Filesystem access |
| v5 | Jun 30, 2026, 04:13 AM | No confirmed findings | 3 | Filesystem access |
| v4 | Jan 17, 2026, 06:36 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 06:36 AM | No confirmed findings | 0 | External commandsNetwork access |
| v2 | Jan 5, 2026, 03:54 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 5, 2026, 03:54 AM | No confirmed findings | 0 | Baseline |
Aug 7, 2026, 09:58 AM
All 54 static findings are false positives. The detected backticks are Markdown examples or command references, the URLs are documentation links, and the reconnaissance matches are ordinary editorial guidance; no prompt injection or malicious intent was found in SKILL.md.
Risk Factors
⚙️ External commands (37)
Jul 23, 2026, 06:45 PM
All 48 static findings are false positives caused by Markdown backticks, read-only repository queries, trusted reference links, and ordinary prose. One high-severity semantic issue remains because the workflow treats untrusted pull request comments as operational instructions.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (31)
Jul 8, 2026, 02:25 AM
Most static matches are false positives caused by Markdown inline code, fenced examples, and hardcoded documentation or issue links in SKILL.md. The skill requests read-only git, GitHub CLI, and web research for changelog maintenance, with no evidence of credential theft or data exfiltration. One semantic risk remains: PR comments are used as process guidance and must be treated as untrusted content.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (31)
Jul 5, 2026, 06:43 PM
All static findings were false positives caused by Markdown inline code, fenced examples, documentation links, and changelog references in SKILL.md. No executable script, data exfiltration intent, prompt injection attempt, or system reconnaissance behavior was found.
Risk Factors
⚙️ External commands (42)
Jun 30, 2026, 04:13 AM
Static analysis found many shell, URL, weak crypto, and reconnaissance patterns in SKILL.md. Review confirms the shell and network items are expected for changelog maintenance, while the weak crypto and reconnaissance alerts are false positives from Markdown text, examples, and filenames. No evidence found for prompt injection, credential theft, destructive commands, or malicious exfiltration.
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
📁 Filesystem access (3)
⚙️ External commands (5)
🌐 Network access (6)
Detected Patterns
Jan 17, 2026, 06:36 AM
This is a pure documentation skill containing only markdown instructions. It provides guidelines for maintaining the IdeaVim changelog and contains NO executable code, network calls, or file operations. All 110 static findings are false positives from the analyzer misinterpreting markdown code block syntax as shell commands and documentation URLs as network indicators.
Risk Factors
⚙️ External commands (55)
Jan 17, 2026, 06:36 AM
This is a pure documentation skill containing only markdown instructions. It provides guidelines for maintaining the IdeaVim changelog and contains NO executable code, network calls, or file operations. All 110 static findings are false positives from the analyzer misinterpreting markdown code block syntax as shell commands and documentation URLs as network indicators.
Risk Factors
⚙️ External commands (55)
Jan 5, 2026, 03:54 AM
This is a pure documentation skill with no executable code. It provides instructions for maintaining the IdeaVim changelog and contains no security risks.
Jan 5, 2026, 03:54 AM
This is a pure documentation skill with no executable code. It provides instructions for maintaining the IdeaVim changelog and contains no security risks.