Audit History
memory-systems - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Aug 4, 2026, 01:53 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 7, 2026, 12:22 AM | No confirmed findings | 0 | No capability change |
| v3 | Jul 7, 2026, 12:22 AM | No confirmed findings | 0 | External commandsNetwork access |
| v2 | Jun 30, 2026, 05:09 PM | 2 confirmed | 0 | No capability change |
| v1 | Feb 25, 2026, 09:43 AM | No confirmed findings | 0 | Baseline |
Aug 4, 2026, 01:53 PM
All nine static findings are false positives caused by Markdown fences, documentation prose, a parameterized query example, and source metadata. No executable shell commands, active network requests, reconnaissance behavior, prompt injection, or malicious intent were found.
Risk Factors
⚙️ External commands (3)
🌐 Network access (1)
Jul 7, 2026, 12:22 AM
The static findings are false positives caused by Markdown code fences, source metadata, and benign memory-system examples. I found no prompt injection, malicious intent, command execution behavior, or unauthorized network behavior in SKILL.md.
Risk Factors
⚙️ External commands (3)
🌐 Network access (1)
Jul 7, 2026, 12:22 AM
The static findings are false positives caused by Markdown code fences, source metadata, and benign memory-system examples. I found no prompt injection, malicious intent, command execution behavior, or unauthorized network behavior in SKILL.md.
Risk Factors
⚙️ External commands (3)
🌐 Network access (1)
Jun 30, 2026, 05:09 PM
Static analysis flagged external commands, weak cryptography, reconnaissance terms, and one URL, but context shows these are documentation false positives. The file contains Markdown guidance and conceptual examples only, with no executable command launcher, cryptographic implementation, data collection, or outbound network behavior.
Confirmed security concerns (2)
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Feb 25, 2026, 09:43 AM
Educational documentation skill for AI memory architecture design. All 28 static analysis findings are false positives from pattern matching on documentation text. The skill contains no executable code, no network calls, no command execution, and no cryptographic operations. It provides conceptual guidance on memory layers, knowledge graphs, and retrieval patterns.