Audit History
game-development - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 23, 2026, 11:11 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 8, 2026, 10:29 AM | No confirmed findings | 0 | No capability change |
| v3 | Jul 6, 2026, 11:37 PM | No confirmed findings | 0 | No capability change |
| v2 | Jun 30, 2026, 04:33 PM | 1 confirmed | 0 | External commands |
| v1 | Feb 25, 2026, 01:51 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 11:11 PM
All 52 static findings are false positives. External-command detections are Markdown fences or inline references, while reconnaissance detections are ordinary game-development guidance. No executable commands, prompt injection, or malicious intent were found.
Risk Factors
⚙️ External commands (41)
Jul 8, 2026, 10:29 AM
The static findings are false positives caused by Markdown code fences, inline code spans, and game design terminology. I found no evidence of command execution, system reconnaissance, prompt injection, data exfiltration, or malicious intent in the reviewed skill files.
Risk Factors
⚙️ External commands (41)
Jul 6, 2026, 11:37 PM
All static findings are false positives caused by Markdown code fences, inline skill names, and ordinary game-development terminology. I found no prompt injection, command execution instructions, credential handling, network calls, or data exfiltration intent in the reviewed files.
Risk Factors
⚙️ External commands (29)
Jun 30, 2026, 04:33 PM
Static analysis reported weak cryptography, reconnaissance, and shell execution patterns, but review found documentation text and markdown formatting rather than executable behavior. The only retained risk factor is external command capability because two skill manifests declare Bash access, with no malicious command guidance found.
Confirmed security concerns (1)
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (2)
Feb 25, 2026, 01:51 AM
All 11 skill files are documentation-only markdown files containing game development principles and guidelines. Static analysis flagged 67 'weak cryptographic algorithm' patterns and 41 'external_commands' patterns, but these are FALSE POSITIVES caused by markdown formatting (code blocks using backticks) and conceptual examples, not actual executable code. No security risks detected. Safe for publication.