Audit History
task-estimation - 4 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v4 Latest | Jul 7, 2026, 06:52 AM | No confirmed findings | 0 | No capability change |
| v3 | Jul 7, 2026, 06:52 AM | No confirmed findings | 0 | External commandsNetwork access |
| v2 | Jun 30, 2026, 11:38 PM | No confirmed findings | 0 | No capability change |
| v1 | Mar 18, 2026, 08:23 AM | No confirmed findings | 0 | Baseline |
Jul 7, 2026, 06:52 AM
All external command findings are false positives from Markdown code fences and inline tags. The URL findings are reference links only, with no prompt injection or exfiltration intent found.
Risk Factors
⚙️ External commands (11)
🌐 Network access (3)
Jul 7, 2026, 06:52 AM
All external command findings are false positives from Markdown code fences and inline tags. The URL findings are reference links only, with no prompt injection or exfiltration intent found.
Risk Factors
⚙️ External commands (11)
🌐 Network access (3)
Jun 30, 2026, 11:38 PM
Static analysis flagged markdown fences, inline backticks, external reference links, and weak-crypto patterns. Manual review found no executable commands, no cryptographic code, no automatic network access, and no prompt injection attempt. The skill is documentation-only agile estimation guidance and is safe to publish.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Mar 18, 2026, 08:23 AM
All static analysis findings are false positives. The skill is purely documentation providing agile estimation templates and guidelines. Markdown code fences (```) were incorrectly flagged as shell execution. Reference URLs are documentation links, not network calls. No executable code, sensitive operations, or security risks present.