Audit History
godot-4-migration - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 24, 2026, 12:30 AM | No confirmed findings | 0 | No capability change |
| v4 | Jul 8, 2026, 11:40 AM | No confirmed findings | 0 | No capability change |
| v3 | Jul 7, 2026, 01:11 AM | No confirmed findings | 0 | External commands |
| v2 | Jun 30, 2026, 04:23 PM | No confirmed findings | 0 | No capability change |
| v1 | Feb 25, 2026, 02:51 AM | No confirmed findings | 0 | Baseline |
Jul 24, 2026, 12:30 AM
All 33 external-command detections are Markdown backticks used for Godot names or fenced GDScript examples; none invokes a shell. The reconnaissance detection is an ordinary Godot error message, and no prompt injection or malicious intent appears in SKILL.md.
Risk Factors
⚙️ External commands (33)
Jul 8, 2026, 11:40 AM
The static external command alerts are false positives caused by Markdown inline code and GDScript examples in SKILL.md. The system reconnaissance alert is also a false positive because it is a Godot troubleshooting heading. No prompt injection, data exfiltration, network access, or command execution intent was found.
Risk Factors
⚙️ External commands (33)
Jul 7, 2026, 01:11 AM
All static findings are false positives caused by Markdown backticks, GDScript code fences, and a quoted Godot error message. No prompt injection, data exfiltration, command execution instructions, or system reconnaissance behavior was found in SKILL.md.
Risk Factors
⚙️ External commands (33)
Jun 30, 2026, 04:23 PM
Static analysis flagged Markdown backticks, weak cryptography, and reconnaissance patterns, but review found only prose and GDScript examples. No shell execution, cryptographic operation, system probing, network access, data exfiltration, or prompt injection text was found in SKILL.md.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Feb 25, 2026, 02:51 AM
All static findings are false positives. The skill contains only documentation for Godot 4 migration with GDScript code examples. No shell commands, cryptographic code, or system reconnaissance present.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.