Audit History
ml-engineer - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Aug 4, 2026, 02:27 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 7, 2026, 12:59 AM | No confirmed findings | 0 | No capability change |
| v3 | Jul 7, 2026, 12:59 AM | No confirmed findings | 0 | No capability change |
| v2 | Jun 30, 2026, 04:21 PM | No confirmed findings | 0 | External commands |
| v1 | Feb 25, 2026, 10:19 AM | No confirmed findings | 0 | Baseline |
Aug 4, 2026, 02:27 PM
Both static findings are false positives caused by ordinary Markdown prose. The skill contains no executable shell command, system reconnaissance behavior, or semantic evidence of malicious intent.
Risk Factors
⚙️ External commands (1)
Jul 7, 2026, 12:59 AM
The two static findings are false positives. The first is a markdown reference to a resource file, and the second is a recommendation systems capability statement. No prompt injection, exfiltration intent, or unsafe execution behavior was found in SKILL.md.
Risk Factors
⚙️ External commands (1)
Jul 7, 2026, 12:59 AM
The two static findings are false positives. The first is a markdown reference to a resource file, and the second is a recommendation systems capability statement. No prompt injection, exfiltration intent, or unsafe execution behavior was found in SKILL.md.
Risk Factors
⚙️ External commands (1)
Jun 30, 2026, 04:21 PM
Static analysis reported one external command pattern, four weak cryptography patterns, and one system reconnaissance pattern in SKILL.md. Review found these are false positives caused by Markdown backticks and machine learning terminology, not executable code or malicious behavior. No prompt injection, data exfiltration, or hidden execution intent was found.
Static false positives ignored (6)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (1)
Feb 25, 2026, 10:19 AM
Prompt-only skill with no executable code. Static analysis found 0 files with executable content and computed risk score of 0/100. The SKILL.md file contains only markdown documentation and AI assistant instructions for ML engineering tasks. No security concerns identified.