Audit History
azure-monitor-opentelemetry-ts - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 23, 2026, 10:01 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 8, 2026, 12:27 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 5, 2026, 11:35 PM | No confirmed findings | 0 | No capability change |
| v2 | Jun 30, 2026, 01:09 PM | 2 confirmed | 0 | External commands |
| v1 | Feb 25, 2026, 01:41 AM | No confirmed findings | 1 | Baseline |
Jul 23, 2026, 10:01 PM
All 52 static findings are false positives caused by Markdown code fences, expected Azure Monitor examples, and OpenTelemetry method names. The skill contains documentation only, with no executable scripts, prompt injection, credential harvesting, or undeclared network destination.
Risk Factors
⚙️ External commands (34)
🌐 Network access (1)
🔑 Env variables (10)
Jul 8, 2026, 12:27 PM
Static analysis flagged Markdown code fences, command examples, environment variable examples, and a placeholder Azure ingestion URL. Review found these patterns are legitimate Azure Monitor OpenTelemetry documentation, with no evidence of prompt injection, credential theft, or unauthorized execution. No semantic security findings were identified.
Risk Factors
⚙️ External commands (34)
🌐 Network access (1)
🔑 Env variables (10)
Jul 5, 2026, 11:35 PM
AI review found the static findings are false positives from Markdown code fences, fixed setup commands, and normal Azure Monitor configuration examples. The skill is documentation-only and shows no prompt injection language, secret exfiltration, or system reconnaissance intent.
Risk Factors
⚙️ External commands (34)
🌐 Network access (1)
🔑 Env variables (10)
Jun 30, 2026, 01:09 PM
Static findings for shell execution, weak cryptography, and system reconnaissance are false positives caused by Markdown code fences, package names, and TypeScript method names. The skill is a documentation guide for Azure Monitor OpenTelemetry, but it legitimately instructs users to export telemetry and use environment-held connection strings, so publication should include a data and credential handling warning.
Confirmed security concerns (2)
Static false positives ignored (4)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (3)
🌐 Network access (2)
🔑 Env variables (10)
Detected Patterns
Feb 25, 2026, 01:41 AM
All static analysis findings are false positives. The scanner analyzed SKILL.md documentation as executable code. The skill provides legitimate Azure Monitor OpenTelemetry instrumentation guidance with standard environment variable configuration and documented network endpoints for telemetry export.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.