Audit History
blockchain-developer - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Aug 14, 2026, 10:35 AM | No confirmed findings | 0 | No capability change |
| v4 | Jul 6, 2026, 11:43 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 6, 2026, 11:43 PM | No confirmed findings | 0 | External commands |
| v2 | Jun 30, 2026, 01:15 PM | 5 confirmed | 0 | No capability change |
| v1 | Feb 25, 2026, 04:21 AM | No confirmed findings | 0 | Baseline |
Aug 14, 2026, 10:35 AM
All three static findings are false positives caused by Markdown formatting or descriptive security guidance. No executable commands, secret collection, reconnaissance behavior, prompt injection, or malicious intent were found.
Risk Factors
⚙️ External commands (1)
Jul 6, 2026, 11:43 PM
I reviewed all three static findings in SKILL.md and found them to be false positives. The flagged text is domain guidance and Markdown formatting, with no evidence of command execution, secret collection, reconnaissance, or prompt injection.
Risk Factors
⚙️ External commands (1)
Jul 6, 2026, 11:43 PM
I reviewed all three static findings in SKILL.md and found them to be false positives. The flagged text is domain guidance and Markdown formatting, with no evidence of command execution, secret collection, reconnaissance, or prompt injection.
Risk Factors
⚙️ External commands (1)
Jun 30, 2026, 01:15 PM
Static analysis flagged shell execution, sensitive key terminology, Cobalt Strike wording, weak cryptography keywords, and reconnaissance wording. Manual review found these are false positives in documentation prose, with no executable code, prompt injection, or exfiltration behavior found.
Confirmed security concerns (5)
Feb 25, 2026, 04:21 AM
Prompt-only skill with no executable code. Static analysis scanned 0 files and detected 0 security issues. The skill provides guidance for blockchain development without any code execution capabilities, network access, filesystem operations, or external command execution. No security risks identified.