Audit History
typeset - 4 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v4 Latest | Jul 6, 2026, 08:49 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 6, 2026, 08:49 PM | No confirmed findings | 0 | External commands |
| v2 | Jun 30, 2026, 10:46 AM | No confirmed findings | 0 | No capability change |
| v1 | Mar 24, 2026, 08:23 AM | No confirmed findings | 0 | Baseline |
Jul 6, 2026, 08:49 PM
All static findings are false positives caused by Markdown inline code around CSS and typography terms. No executable commands, system reconnaissance, prompt injection, network access, or data exfiltration intent were found in SKILL.md.
Risk Factors
⚙️ External commands (11)
Jul 6, 2026, 08:49 PM
All static findings are false positives caused by Markdown inline code around CSS and typography terms. No executable commands, system reconnaissance, prompt injection, network access, or data exfiltration intent were found in SKILL.md.
Risk Factors
⚙️ External commands (11)
Jun 30, 2026, 10:46 AM
Static analysis reported external command, weak cryptography, and reconnaissance patterns in SKILL.md. Manual review found markdown prose and inline CSS examples, with no executable code, network access, credential handling, or prompt injection attempt.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Mar 24, 2026, 08:23 AM
All 26 static analysis findings are false positives. The scanner misinterpreted CSS code snippets (e.g., font-display, max-width, tabular-nums) as shell commands and typography analysis instructions as system reconnaissance. This is a design guideline document with no executable code, network access, filesystem operations, or cryptographic functions. Safe for publication.