Audit History
documentation-templates - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 23, 2026, 10:50 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 8, 2026, 12:23 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 6, 2026, 10:55 PM | No confirmed findings | 0 | External commands |
| v2 | Jun 30, 2026, 02:41 PM | No confirmed findings | 0 | No capability change |
| v1 | Feb 24, 2026, 09:31 PM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 10:50 PM
All 15 static findings are false positives caused by fenced documentation examples and ordinary template wording. The skill contains no executable commands, system reconnaissance, prompt injection, or other semantic security concerns.
Risk Factors
Jul 8, 2026, 12:23 PM
The static command findings are false positives caused by fenced markdown and TypeScript examples in SKILL.md. The reconnaissance findings are documentation examples, not instructions to inspect a system or collect host data. No prompt injection, data exfiltration, or malicious intent evidence found.
Risk Factors
Jul 6, 2026, 10:55 PM
All static findings are false positives caused by Markdown fences and generic documentation placeholders in SKILL.md. No prompt injection, executable command behavior, data exfiltration intent, or system reconnaissance intent was found.
Risk Factors
Jun 30, 2026, 02:41 PM
Static analysis reported command execution, weak cryptography, and reconnaissance patterns, but review found they are false positives from Markdown fences and example text. The skill contains only documentation templates and requests read-only tools, with no executable scripts, network calls, secret access, or prompt injection attempts.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Feb 24, 2026, 09:31 PM
All 23 static findings are false positives. The skill contains only markdown documentation templates with no executable code. The detected patterns (external_commands, weak cryptographic algorithms, system reconnaissance) are markdown code fences, plain English text, and API documentation placeholders - not actual security risks.