Audit History
harden - 4 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v4 Latest | Jul 6, 2026, 08:22 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 6, 2026, 08:22 PM | No confirmed findings | 0 | External commands |
| v2 | Jun 30, 2026, 11:23 AM | No confirmed findings | 0 | No capability change |
| v1 | Mar 16, 2026, 08:34 AM | No confirmed findings | 0 | Baseline |
Jul 6, 2026, 08:22 PM
All static findings are false positives caused by Markdown code fences, inline code formatting, or frontend layout terminology in SKILL.md. No evidence found of external command execution, system reconnaissance, data exfiltration, prompt injection, or other malicious intent.
Risk Factors
⚙️ External commands (21)
Jul 6, 2026, 08:22 PM
All static findings are false positives caused by Markdown code fences, inline code formatting, or frontend layout terminology in SKILL.md. No evidence found of external command execution, system reconnaissance, data exfiltration, prompt injection, or other malicious intent.
Risk Factors
⚙️ External commands (21)
Jun 30, 2026, 11:23 AM
Static analysis reported shell execution, weak cryptography, and reconnaissance patterns. Manual review found a Markdown-only frontend hardening guide with CSS, JSX, JavaScript, and HTML examples, not executable scripts. No prompt injection, data exfiltration, network access, or malicious intent was found.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Mar 16, 2026, 08:34 AM
Static analysis detected 34 potential issues but all are false positives from markdown code blocks and comments. The skill contains only educational documentation with CSS/JS code examples. No executable code, network calls, file system access, or external commands present. This is a purely instructional skill about UI hardening best practices.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.