Audit History
data-storytelling - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 23, 2026, 10:19 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 8, 2026, 10:27 AM | No confirmed findings | 0 | No capability change |
| v3 | Jul 6, 2026, 11:03 PM | No confirmed findings | 0 | External commands |
| v2 | Jun 30, 2026, 03:04 PM | 1 confirmed | 0 | Network access |
| v1 | Feb 24, 2026, 06:50 PM | 1 confirmed | 0 | Baseline |
Jul 23, 2026, 10:19 PM
All 36 static detections are false positives caused by Markdown code fences, business example language, and ordinary reference links. The skill contains no command execution, automated network requests, prompt injection, or other malicious behavior.
Risk Factors
⚙️ External commands (28)
🌐 Network access (3)
Jul 8, 2026, 10:27 AM
Review found no executable command behavior or unsafe automation in SKILL.md. Static command findings are Markdown fences and inline references, while URL and reconnaissance findings are resource links or business examples.
Risk Factors
⚙️ External commands (28)
🌐 Network access (3)
Jul 6, 2026, 11:03 PM
All 36 static findings were adjudicated as false positives. The flagged backticks are markdown formatting, the URLs are reference links, and the reconnaissance hits are business examples. No prompt injection or malicious intent was found in SKILL.md.
Risk Factors
⚙️ External commands (28)
🌐 Network access (3)
Jun 30, 2026, 03:04 PM
Static command execution alerts are false positives caused by markdown code fences, presentation templates, diagrams, and a plotting example. The only confirmed risk factor is low-risk network exposure from three external resource links, with no evidence of automatic requests, exfiltration, prompt injection, or malicious intent.
Confirmed security concerns (1)
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (3)
Feb 24, 2026, 06:50 PM
This skill is a pure documentation and guide resource for data storytelling. All static findings are false positives: backticks are markdown inline code syntax (not shell execution), URLs are legitimate reference links to published books, and no cryptographic algorithms or reconnaissance code exists. The skill contains only text-based frameworks, templates, and writing techniques.