Audit History
analytics-tracking - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 23, 2026, 07:05 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 8, 2026, 08:12 AM | No confirmed findings | 0 | No capability change |
| v3 | Jul 6, 2026, 08:06 PM | No confirmed findings | 0 | External commands |
| v2 | Jun 30, 2026, 11:01 AM | No confirmed findings | 0 | No capability change |
| v1 | Feb 24, 2026, 05:35 PM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 07:05 PM
Both static findings are false positives caused by Markdown and analytics terminology in SKILL.md. The skill contains advisory measurement guidance, with no executable commands, system reconnaissance, prompt injection, or data-exfiltration intent.
Risk Factors
⚙️ External commands (1)
Jul 8, 2026, 08:12 AM
Both static findings are false positives after context review. The detected backticks are a Markdown code fence for an event naming pattern, and the container reference is GA4/GTM guidance, not system reconnaissance.
Risk Factors
⚙️ External commands (1)
Jul 6, 2026, 08:06 PM
The static findings were reviewed against SKILL.md context. Both flagged locations are benign markdown or analytics guidance, and no prompt injection or malicious intent was found.
Risk Factors
⚙️ External commands (1)
Jun 30, 2026, 11:01 AM
The static findings are false positives caused by analytics terminology and a Markdown event naming example. No executable scripts, shell commands, weak cryptographic usage, reconnaissance behavior, network calls, or prompt injection attempts were found.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Feb 24, 2026, 05:35 PM
This is a prompt-only skill containing only documentation and guidance in SKILL.md. No executable code, scripts, network calls, or filesystem operations detected. Static analysis correctly identified zero security risks. The skill provides analytics measurement strategy guidance without any code execution capabilities.