Audit History
ai-engineer - 6 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v6 Latest | Jul 23, 2026, 08:41 PM | No confirmed findings | 0 | No capability change |
| v5 | Jul 8, 2026, 07:40 AM | No confirmed findings | 0 | No capability change |
| v4 | Jul 6, 2026, 08:49 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 6, 2026, 08:49 PM | No confirmed findings | 0 | No capability change |
| v2 | Jun 30, 2026, 10:44 AM | No confirmed findings | 0 | No capability change |
| v1 | Feb 24, 2026, 04:58 PM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 08:41 PM
All four static findings are false positives caused by safety and information-retrieval terminology in SKILL.md. The file contains guidance only and does not direct system reconnaissance, jailbreak behavior, code execution, or data exfiltration. No net-new semantic security risks were found.
Jul 8, 2026, 07:40 AM
The flagged lines are false positives from security or retrieval terminology in a prompt-based AI engineering skill. I found no evidence in SKILL.md of prompt injection, data exfiltration intent, malware behavior, or unsafe execution instructions.
Jul 6, 2026, 08:49 PM
All four static findings are false positives after context review. The skill discusses safety controls, hybrid retrieval, and RAG examples without prompt injection, data exfiltration, or unsafe reconnaissance intent.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Jul 6, 2026, 08:49 PM
All four static findings are false positives after context review. The skill discusses safety controls, hybrid retrieval, and RAG examples without prompt injection, data exfiltration, or unsafe reconnaissance intent.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Jun 30, 2026, 10:44 AM
Static analysis reported weak cryptography, reconnaissance, and jailbreak-keyword patterns in SKILL.md. Manual review found these are defensive or descriptive Markdown references, not executable code, command usage, network access, or prompt injection. No confirmed malicious behavior or hidden semantic risk was found.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Feb 24, 2026, 04:58 PM
Prompt-only skill with no executable code. Static analysis scanned 0 files (0 lines) and detected 0 potential security issues. Risk score: 0/100. This is a text-based persona prompt for AI engineering tasks with no scripts, network calls, filesystem access, or external command execution. No prompt injection attempts detected.