Audit History
monday-automation - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Aug 4, 2026, 02:50 PM | 1 confirmed | 1 | No capability change |
| v4 | Jul 7, 2026, 01:22 AM | No confirmed findings | 0 | No capability change |
| v3 | Jul 7, 2026, 01:22 AM | No confirmed findings | 0 | External commands |
| v2 | Jun 30, 2026, 04:48 PM | 2 confirmed | 1 | External commands |
| v1 | Feb 25, 2026, 10:46 AM | No confirmed findings | 0 | Baseline |
Aug 4, 2026, 02:50 PM
All 117 external-command alerts are Markdown backticks, and all three reconnaissance alerts are contextual false positives. The external MCP endpoint is a real low-risk network dependency. Raw GraphQL guidance adds medium risk because destructive mutations lack confirmation controls.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (50)
🌐 Network access (1)
Jul 7, 2026, 01:22 AM
All static findings were reviewed against SKILL.md context. The backtick detections are Markdown inline code for Rube MCP and Monday.com tool names, parameters, and examples; no executable shell behavior or prompt injection was found.
Risk Factors
⚙️ External commands (117)
🌐 Network access (1)
Jul 7, 2026, 01:22 AM
All static findings were reviewed against SKILL.md context. The backtick detections are Markdown inline code for Rube MCP and Monday.com tool names, parameters, and examples; no executable shell behavior or prompt injection was found.
Risk Factors
⚙️ External commands (117)
🌐 Network access (1)
Jun 30, 2026, 04:48 PM
Static external-command findings are false positives from Markdown code spans around Monday and Rube tool names. The skill is documentation-only, but it depends on an external Rube MCP endpoint and guides authenticated Monday.com write operations, including raw GraphQL mutations.
Confirmed security concerns (2)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (1)
Detected Patterns
Feb 25, 2026, 10:46 AM
Static analysis detected 191 'external_commands' patterns in SKILL.md, but these are all backtick-enclosed tool names (e.g., `MONDAY_LIST_BOARDS`, `RUBE_SEARCH_TOOLS`) used as markdown code references in documentation. No actual code execution or shell commands present. Network reference is a legitimate HTTPS URL for Rube MCP server endpoint. This is documentation-only content with no executable code.