Audit History
youtrack - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 5, 2026, 06:52 PM | 1 confirmed | 0 | No capability change |
| v6 | Jul 5, 2026, 06:52 PM | 1 confirmed | 0 | No capability change |
| v5 | Jun 30, 2026, 04:19 AM | No confirmed findings | 2 | No capability change |
| v4 | Jan 17, 2026, 06:42 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 06:42 AM | No confirmed findings | 0 | Network accessExternal commands |
| v2 | Jan 4, 2026, 04:32 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 4, 2026, 04:32 PM | No confirmed findings | 0 | Baseline |
Jul 5, 2026, 06:52 PM
Most static findings are Markdown backtick and code-fence false positives, not executable Ruby or hidden shell substitution. The skill still documents YouTrack state-changing workflows, including release version deletion, without explicit approval guardrails. No prompt injection or credential exfiltration intent was found.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (49)
🌐 Network access (1)
Jul 5, 2026, 06:52 PM
Most static findings are Markdown backtick and code-fence false positives, not executable Ruby or hidden shell substitution. The skill still documents YouTrack state-changing workflows, including release version deletion, without explicit approval guardrails. No prompt injection or credential exfiltration intent was found.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (49)
🌐 Network access (1)
Jun 30, 2026, 04:19 AM
Static external-command findings are true in the sense that the skill documents many npx tsx commands, but they are not Ruby backtick execution. The commands are legitimate YouTrack workflows, yet they can mutate tickets through a token-backed external service, so publication should include a warning. The hardcoded URL is the expected JetBrains YouTrack host, and the weak-cryptography finding at SKILL.md line 3 appears to be a false positive.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (12)
🌐 Network access (1)
Detected Patterns
Jan 17, 2026, 06:42 AM
All 62 static findings are false positives. The scanner incorrectly flagged metadata fields (URLs, hashes) as security risks, documentation text as C2/cryptographic indicators, and code examples as shell execution. This directory contains only documentation (SKILL.md) that explains how to use external YouTrack CLI scripts. No executable code, network calls, or file operations exist in this skill folder.
Risk Factors
🌐 Network access (1)
⚙️ External commands (50)
Jan 17, 2026, 06:42 AM
All 62 static findings are false positives. The scanner incorrectly flagged metadata fields (URLs, hashes) as security risks, documentation text as C2/cryptographic indicators, and code examples as shell execution. This directory contains only documentation (SKILL.md) that explains how to use external YouTrack CLI scripts. No executable code, network calls, or file operations exist in this skill folder.
Risk Factors
🌐 Network access (1)
⚙️ External commands (50)
Jan 4, 2026, 04:32 PM
The directory contains documentation and metadata only. No executable code, scripts, or network-capable logic are present here.
Jan 4, 2026, 04:32 PM
The directory contains documentation and metadata only. No executable code, scripts, or network-capable logic are present here.