Audit History
swarm-advanced - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 23, 2026, 07:33 PM | No confirmed findings | 4 | No capability change |
| v7 | Jul 8, 2026, 08:11 AM | No confirmed findings | 0 | No capability change |
| v6 | Jul 5, 2026, 08:51 PM | No confirmed findings | 0 | No capability change |
| v5 | Jun 30, 2026, 10:38 AM | 2 confirmed | 0 | No capability change |
| v4 | Jan 17, 2026, 07:57 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 07:57 AM | No confirmed findings | 0 | Network accessExternal commands |
| v2 | Jan 6, 2026, 08:12 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 6, 2026, 08:12 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 07:33 PM
Most alerts are false positives caused by Markdown fences, inline names, documentation links, and ordinary guidance. Four findings are confirmed because examples execute community npm packages through global installation or unversioned npx commands. No prompt injection, exfiltration intent, or malicious behavior was found.
Capability review items (4)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (50)
🌐 Network access (4)
Jul 8, 2026, 08:11 AM
The static backtick detections are Markdown code fences or inline-code examples in SKILL.md, not executable Ruby shell backticks. The hardcoded URLs are GitHub reference links, and the system reconnaissance hit is ordinary best-practice prose. No prompt injection, hidden exfiltration, or executable payload was found in the single-file skill.
Risk Factors
⚙️ External commands (67)
🌐 Network access (4)
Jul 5, 2026, 08:51 PM
All 72 static findings are false positives from Markdown fences, inline code, CLI examples, and reference links. No evidence found of prompt injection, credential access, exfiltration, or automatic network activity. The skill is instructional content for Claude Flow swarm orchestration.
Risk Factors
⚙️ External commands (67)
🌐 Network access (4)
Jun 30, 2026, 10:38 AM
Static analysis found many command-execution and network patterns, but most are Markdown examples for Claude Flow MCP calls rather than executable code. The real risk is instructional: the skill tells users to install an external alpha package and register an MCP server, so publishing is acceptable with a warning. The weak cryptography and system reconnaissance hits were false positives caused by ordinary text, headings, and comments.
Confirmed security concerns (2)
Static false positives ignored (4)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (67)
🌐 Network access (4)
Detected Patterns
Jan 17, 2026, 07:57 AM
Pure documentation skill containing only SKILL.md with MCP tool usage patterns and CLI examples. No executable code, scripts, or malicious patterns detected. All 90 static findings are FALSE POSITIVES - the markdown code blocks and GitHub URLs flagged by the analyzer are standard documentation elements, not security risks.
Risk Factors
🌐 Network access (4)
⚙️ External commands (67)
Jan 17, 2026, 07:57 AM
Pure documentation skill containing only SKILL.md with MCP tool usage patterns and CLI examples. No executable code, scripts, or malicious patterns detected. All 90 static findings are FALSE POSITIVES - the markdown code blocks and GitHub URLs flagged by the analyzer are standard documentation elements, not security risks.
Risk Factors
🌐 Network access (4)
⚙️ External commands (67)
Jan 6, 2026, 08:12 AM
Pure documentation skill containing only SKILL.md with MCP tool usage patterns. No executable code, scripts, or malicious patterns. Contains CLI command references for Claude Flow integration, which is expected for orchestration skills.
Jan 6, 2026, 08:12 AM
Pure documentation skill containing only SKILL.md with MCP tool usage patterns. No executable code, scripts, or malicious patterns. Contains CLI command references for Claude Flow integration, which is expected for orchestration skills.