Audit History
game-changing-features - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 7, 2026, 04:54 AM | No confirmed findings | 0 | No capability change |
| v4 | Jul 7, 2026, 04:54 AM | No confirmed findings | 0 | External commands Filesystem access |
| v3 | Jun 30, 2026, 07:39 PM | No confirmed findings | 1 | No capability change |
| v2 | Jun 30, 2026, 07:39 PM | No confirmed findings | 1 | Filesystem access External commands |
| v1 | Feb 2, 2026, 09:02 AM | No confirmed findings | 0 | Baseline |
Jul 7, 2026, 04:54 AM
All seven static findings are false positives. The flagged locations are Markdown paths, fenced output templates, and ordinary product strategy wording, with no executable command usage or reconnaissance behavior found.
Risk Factors
⚙️ External commands (5)
Jul 7, 2026, 04:54 AM
All seven static findings are false positives. The flagged locations are Markdown paths, fenced output templates, and ordinary product strategy wording, with no executable command usage or reconnaissance behavior found.
Risk Factors
⚙️ External commands (5)
Jun 30, 2026, 07:39 PM
AI review found the static command execution, weak cryptography, network reconnaissance, and system reconnaissance alerts to be false positives caused by markdown formatting, examples, paths, and 10x product-strategy language. No executable code, shell invocation, cryptographic implementation, network probing, credential access, or prompt-injection override was found. The skill has a low risk because it instructs agents to save strategy outputs under .claude/docs.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
📁 Filesystem access (3)
Jun 30, 2026, 07:39 PM
AI review found the static command execution, weak cryptography, network reconnaissance, and system reconnaissance alerts to be false positives caused by markdown formatting, examples, paths, and 10x product-strategy language. No executable code, shell invocation, cryptographic implementation, network probing, credential access, or prompt-injection override was found. The skill has a low risk because it instructs agents to save strategy outputs under .claude/docs.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
📁 Filesystem access (3)
Feb 2, 2026, 09:02 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.