Audit History
azure-servicebus-ts - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 23, 2026, 11:05 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 8, 2026, 01:34 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 6, 2026, 10:27 PM | No confirmed findings | 0 | External commands |
| v2 | Jun 30, 2026, 12:58 PM | No confirmed findings | 1 | Env variables |
| v1 | Feb 25, 2026, 03:03 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 11:05 PM
All 39 static alerts are false positives caused by Markdown fences, TypeScript template literals, a normal namespace environment variable, and security guidance. No executable Ruby backticks, sensitive file access, system reconnaissance, prompt injection, or malicious intent were found.
Risk Factors
⚙️ External commands (35)
🔑 Env variables (2)
Jul 8, 2026, 01:34 PM
No executable shell logic or prompt injection was found in the skill source. The static findings are Markdown fences, TypeScript examples, documented Azure SDK setup, or a non-secret namespace environment variable.
Risk Factors
⚙️ External commands (35)
🔑 Env variables (2)
Jul 6, 2026, 10:27 PM
The static findings are false positives caused by Markdown fences, TypeScript template literals, inline code names, and one environment variable example. No prompt injection, credential exfiltration, destructive command execution, or malicious intent was found in SKILL.md.
Risk Factors
⚙️ External commands (35)
🔑 Env variables (2)
Jun 30, 2026, 12:58 PM
Static analysis reported many command execution, weak cryptography, environment access, and reconnaissance patterns. Manual review found the command and weak-crypto detections are false positives from markdown fences, prose, and SDK examples; the only real risk factor is a normal process.env namespace lookup in sample TypeScript.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🔑 Env variables (2)
Feb 25, 2026, 03:03 AM
All 46 static findings are false positives. The skill is legitimate Azure Service Bus documentation containing code examples in markdown. The backtick patterns are from markdown code fences, not shell execution. Environment variable access is for Azure configuration (standard practice). No cryptographic algorithms or malicious patterns present.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.