Audit History
ai-product - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 23, 2026, 08:46 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 8, 2026, 07:47 AM | No confirmed findings | 0 | External commandsNetwork access |
| v3 | Jul 6, 2026, 08:54 PM | No confirmed findings | 0 | No capability change |
| v2 | Jun 30, 2026, 10:48 AM | No confirmed findings | 0 | No capability change |
| v1 | Feb 24, 2026, 05:02 PM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 08:46 PM
All 35 static findings are false positives caused by TypeScript template literals, Markdown fences, ordinary prose, or quoted defensive examples. The skill contains educational guidance and illustrative code, with no executable shell commands, credential access, reconnaissance, or malicious prompt injection.
Risk Factors
⚙️ External commands (27)
🌐 Network access (3)
Jul 8, 2026, 07:47 AM
Static findings are false positives caused by Markdown code fences, TypeScript examples, and quoted anti-pattern text in SKILL.md. I found no executable scripts, real network access, sensitive file handling, or active prompt-injection directive.
Risk Factors
⚙️ External commands (27)
🌐 Network access (3)
Jul 6, 2026, 08:54 PM
I reviewed the prompt-only SKILL.md and found no static findings to adjudicate. The content provides AI product engineering guidance and does not include code, filesystem access, network calls, or prompt-injection instructions. No semantic abuse or data-exfiltration intent was found.
Jun 30, 2026, 10:48 AM
The static analyzer flagged SKILL.md:3 for a weak cryptographic algorithm, but that line is only a frontmatter description. No evidence found of cryptographic code, scripts, network access, filesystem access, external commands, or prompt injection attempts.
Feb 24, 2026, 05:02 PM
Static analysis detected 2 false positive patterns related to 'weak cryptographic algorithm' at lines 3 and 58. These are misidentified keywords ('patterns', 'architecture') in documentation text. This is a documentation-only skill with no executable code, network calls, scripts, filesystem access, or external commands. Safe for publication.