Audit History
azure-monitor-opentelemetry-exporter-java - 6 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v6 Latest | Jul 23, 2026, 09:51 PM | No confirmed findings | 0 | No capability change |
| v5 | Jul 8, 2026, 12:16 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 6, 2026, 08:41 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 6, 2026, 08:41 PM | No confirmed findings | 0 | No capability change |
| v2 | Jun 30, 2026, 01:02 PM | No confirmed findings | 3 | External commandsNetwork access |
| v1 | Feb 25, 2026, 01:31 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 09:51 PM
All 42 static findings are false positives caused by Markdown backticks, documentation links, metric labels, package paths, and ordinary Java method declarations. The skill contains inert guidance and sample code, with no command execution, credential access, reconnaissance, prompt injection, or malicious intent.
Risk Factors
⚙️ External commands (26)
🌐 Network access (10)
Jul 8, 2026, 12:16 PM
I found no malicious intent, prompt injection, or credential exfiltration in SKILL.md. The static findings are false positives from Markdown formatting, documentation links, placeholder Azure configuration, and Java examples.
Risk Factors
⚙️ External commands (26)
🌐 Network access (10)
Jul 6, 2026, 08:41 PM
Static findings are false positives caused by Markdown code fences, Java examples, placeholder Azure configuration, and reference links. No prompt injection, credential exfiltration intent, or executable installer code was found in SKILL.md. Users should still keep real Application Insights connection strings out of prompts and documentation.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (26)
🌐 Network access (10)
Jul 6, 2026, 08:41 PM
Static findings are false positives caused by Markdown code fences, Java examples, placeholder Azure configuration, and reference links. No prompt injection, credential exfiltration intent, or executable installer code was found in SKILL.md. Users should still keep real Application Insights connection strings out of prompts and documentation.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (26)
🌐 Network access (10)
Jun 30, 2026, 01:02 PM
Static analysis flagged many external command, network, sensitive, and weak crypto patterns, but review found documentation examples rather than executable skill code. The command findings are Markdown code fences and inline package names, while network references are expected Azure Monitor, Maven, GitHub, OpenTelemetry, and Microsoft documentation links. No prompt injection, credential exfiltration, hidden scripts, or malicious intent were found in SKILL.md.
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (12)
🌐 Network access (4)
Feb 25, 2026, 01:31 AM
This is a prompt-only documentation skill containing code examples for using the Azure Monitor OpenTelemetry Exporter library. Static analysis scanned 0 files and detected 0 security issues. The skill provides informational content about a deprecated Microsoft library with migration guidance. No executable code, network calls, or file system access is present in the skill itself.