Audit History
behavioral-modes - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Aug 14, 2026, 10:21 AM | No confirmed findings | 0 | No capability change |
| v4 | Jul 6, 2026, 11:26 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 6, 2026, 11:26 PM | No confirmed findings | 0 | External commands |
| v2 | Jun 30, 2026, 01:02 PM | No confirmed findings | 0 | No capability change |
| v1 | Feb 25, 2026, 04:10 AM | No confirmed findings | 0 | Baseline |
Aug 14, 2026, 10:21 AM
All static alerts are false positives caused by Markdown fences, inline code formatting, filenames, or ordinary instructional text. The skill contains no executable shell logic, system reconnaissance, prompt injection, or other semantic security issue.
Risk Factors
⚙️ External commands (21)
Jul 6, 2026, 11:26 PM
The static findings are false positives caused by Markdown code fences, inline code formatting, and sample output text in SKILL.md. The skill declares only read-oriented tools and contains no executable scripts, network access, secret collection, or prompt injection attempt. No semantic security findings were identified.
Risk Factors
⚙️ External commands (21)
Jul 6, 2026, 11:26 PM
The static findings are false positives caused by Markdown code fences, inline code formatting, and sample output text in SKILL.md. The skill declares only read-oriented tools and contains no executable scripts, network access, secret collection, or prompt injection attempt. No semantic security findings were identified.
Risk Factors
⚙️ External commands (21)
Jun 30, 2026, 01:02 PM
Static analysis reported external command, weak cryptography, and reconnaissance patterns in SKILL.md. Manual review found these are false positives from Markdown code fences, inline backticks, emoji-rich examples, and substring matches in ordinary text; no executable code, network access, secret access, or prompt injection attempt was found.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Feb 25, 2026, 04:10 AM
All 34 static analysis findings are false positives. The SKILL.md file is pure documentation describing behavioral modes with markdown-formatted output examples. No executable code, shell commands, or cryptographic operations exist. The skill only uses read-only tools (Read, Glob, Grep) and provides behavioral guidance for AI interactions.