Audit History
planning-with-files - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 6, 2026, 08:50 PM | No confirmed findings | 0 | No capability change |
| v6 | Jul 6, 2026, 08:50 PM | No confirmed findings | 0 | External commands Filesystem access |
| v5 | Jun 30, 2026, 10:40 AM | 1 confirmed | 0 | Filesystem access External commandsNetwork access |
| v4 | Jan 17, 2026, 08:09 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 08:09 AM | No confirmed findings | 0 | External commandsNetwork access |
| v2 | Jan 5, 2026, 07:48 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 5, 2026, 07:48 AM | No confirmed findings | 0 | Baseline |
Jul 6, 2026, 08:50 PM
The static alerts are false positives caused by markdown backticks, fenced examples, and headings. The reviewed files provide planning workflow guidance and do not contain executable code, prompt injection attempts, credential access, or data exfiltration behavior.
Risk Factors
Jul 6, 2026, 08:50 PM
The static alerts are false positives caused by markdown backticks, fenced examples, and headings. The reviewed files provide planning workflow guidance and do not contain executable code, prompt injection attempts, credential access, or data exfiltration behavior.
Risk Factors
Jun 30, 2026, 10:40 AM
Static analysis reported many external command, weak crypto, browser storage, URL, and dangerous-combination patterns. Review found these are markdown examples, inline filenames, and one documentation link, not executable code or data exfiltration. The only confirmed concern is intentional filesystem use to create and update planning files, so publication is safe with a low-risk label.
Confirmed security concerns (1)
Static false positives ignored (6)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
📁 Filesystem access (6)
Jan 17, 2026, 08:09 AM
Documentation-only skill describing workflow patterns. No executable code, network calls, or credential access. All 68 static findings are false positives: Claude tool examples were misidentified as shell commands, and common words triggered incorrect cryptographic warnings.
Risk Factors
⚙️ External commands (50)
🌐 Network access (1)
Jan 17, 2026, 08:09 AM
Documentation-only skill describing workflow patterns. No executable code, network calls, or credential access. All 68 static findings are false positives: Claude tool examples were misidentified as shell commands, and common words triggered incorrect cryptographic warnings.
Risk Factors
⚙️ External commands (50)
🌐 Network access (1)
Jan 5, 2026, 07:48 AM
This is a documentation-only skill with no executable code. It provides workflow patterns for using markdown files to manage complex tasks. No security risks identified.
Jan 5, 2026, 07:48 AM
This is a documentation-only skill with no executable code. It provides workflow patterns for using markdown files to manage complex tasks. No security risks identified.