📦

Audit History

architecture-decision-records - 7 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v7 LatestJul 7, 2026, 07:26 AM No confirmed findings0No capability change
v6 Jul 7, 2026, 07:26 AM No confirmed findings0No capability change
v5 Jun 30, 2026, 09:47 PM 1 confirmed2No capability change
v4 Jan 17, 2026, 07:08 AM No confirmed findings0No capability change
v3 Jan 17, 2026, 07:08 AM No confirmed findings0Network accessExternal commands
v2 Jan 4, 2026, 04:44 PM No confirmed findings0No capability change
v1 Jan 4, 2026, 04:44 PM No confirmed findings0Baseline

Jul 7, 2026, 07:26 AM

All static findings were adjudicated as false positives. The backtick detections are Markdown fences, inline code, or documented adr-tools examples, and the network detections are ordinary reference links with no evidence of data transfer or hidden access.

1
Files scanned
429
Lines analyzed
2
Review items
0
False positives ignored
Audited by: codex

Jul 7, 2026, 07:26 AM

All static findings were adjudicated as false positives. The backtick detections are Markdown fences, inline code, or documented adr-tools examples, and the network detections are ordinary reference links with no evidence of data transfer or hidden access.

1
Files scanned
429
Lines analyzed
2
Review items
0
False positives ignored
Audited by: codex

Jun 30, 2026, 09:47 PM

Static analysis reported command execution, network, and weak cryptography patterns, but review found documentation-only Markdown examples and reference links. No prompt injection, data exfiltration, automatic execution path, or cryptographic implementation was found in the single SKILL.md file.

1
Files scanned
429
Lines analyzed
5
Review items
0
False positives ignored

Confirmed security concerns (1)

Low
Weak Cryptography Flags Are Prose Collisions
The high-severity weak cryptography detections are false positives from ADR prose and headings. No cryptographic algorithm, hashing function, encryption API, or credential-handling logic is present.
The flagged lines contain natural-language ADR content such as decision, design, accepted, and superseded. No evidence of cryptographic implementation was found.
Capability review items (2)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Low
Markdown Backticks Flagged as Command Execution
The static analyzer flagged fenced Markdown blocks, inline code, and one adr-tools example block as Ruby or shell backtick execution. These lines are documentation examples, and the skill has no executable file or automatic command runner. The adr-tools commands are manual instructions that users should review before running.
Line context shows Markdown code fences, inline code, or a bash documentation block. The reviewed skill contains no implementation that invokes these commands automatically.
Low
Reference URLs Flagged as Network Access
The hardcoded URLs are documentation references for PostgreSQL, Event Sourcing, ADR templates, and adr-tools. No code performs network requests or sends local data to these URLs.
Each flagged URL appears in a References or Resources section. There is no fetch, curl, webhook, or network-capable script in the reviewed file.
Audited by: codex

Jan 17, 2026, 07:08 AM

Pure documentation skill containing only templates and guidance for writing Architecture Decision Records. All 56 static findings are false positives: detected patterns are markdown documentation examples, harmless text strings in prose, and legitimate documentation links. No executable code, file access, network activity, or external commands are present.

2
Files scanned
605
Lines analyzed
2
Review items
0
False positives ignored
Audited by: claude

Jan 17, 2026, 07:08 AM

Pure documentation skill containing only templates and guidance for writing Architecture Decision Records. All 56 static findings are false positives: detected patterns are markdown documentation examples, harmless text strings in prose, and legitimate documentation links. No executable code, file access, network activity, or external commands are present.

2
Files scanned
605
Lines analyzed
2
Review items
0
False positives ignored
Audited by: claude

Jan 4, 2026, 04:44 PM

Pure documentation skill containing only templates and guidance for writing Architecture Decision Records. No executable code, file access, network activity, or external commands are present. All bash commands shown are documentation examples only.

4
Files scanned
428
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 4, 2026, 04:44 PM

Pure documentation skill containing only templates and guidance for writing Architecture Decision Records. No executable code, file access, network activity, or external commands are present. All bash commands shown are documentation examples only.

4
Files scanned
428
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude