Audit History
bazel-build-optimization - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 7, 2026, 08:02 AM | No confirmed findings | 0 | No capability change |
| v7 | Jul 7, 2026, 08:02 AM | No confirmed findings | 0 | No capability change |
| v6 | Jun 30, 2026, 10:10 PM | No confirmed findings | 2 | No capability change |
| v5 | Jun 30, 2026, 10:10 PM | No confirmed findings | 2 | No capability change |
| v4 | Jan 17, 2026, 07:37 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 07:37 AM | No confirmed findings | 0 | Network accessExternal commandsFilesystem access |
| v2 | Jan 4, 2026, 04:49 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 4, 2026, 04:49 PM | No confirmed findings | 0 | Baseline |
Jul 7, 2026, 08:02 AM
The static findings were reviewed in context and appear to be documentation examples, not executable skill code. No prompt injection, credential exfiltration, or unsafe filesystem behavior was found in SKILL.md. The command, URL, cache path, and mnemonic matches are false positives from Markdown examples.
Risk Factors
⚙️ External commands (20)
🌐 Network access (6)
📁 Filesystem access (4)
Jul 7, 2026, 08:02 AM
The static findings were reviewed in context and appear to be documentation examples, not executable skill code. No prompt injection, credential exfiltration, or unsafe filesystem behavior was found in SKILL.md. The command, URL, cache path, and mnemonic matches are false positives from Markdown examples.
Risk Factors
⚙️ External commands (20)
🌐 Network access (6)
📁 Filesystem access (4)
Jun 30, 2026, 10:10 PM
Static analysis flagged command, network, filesystem, crypto, and obfuscation patterns in SKILL.md. Review found these are documentation examples, Bazel templates, placeholder service URLs, checksum fields, and local cache paths, with no evidence of malicious execution or data exfiltration.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (20)
🌐 Network access (6)
📁 Filesystem access (4)
Detected Patterns
Jun 30, 2026, 10:10 PM
Static analysis flagged command, network, filesystem, crypto, and obfuscation patterns in SKILL.md. Review found these are documentation examples, Bazel templates, placeholder service URLs, checksum fields, and local cache paths, with no evidence of malicious execution or data exfiltration.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (20)
🌐 Network access (6)
📁 Filesystem access (4)
Detected Patterns
Jan 17, 2026, 07:37 AM
This is a pure documentation skill containing only instructional markdown content. No executable code, scripts, or functions exist. Static findings are false positives triggered by documentation patterns: 'sha256' in http_archive() calls are integrity checksums for dependency downloads (security best practice), backticks are Markdown code fences, and URL references are documentation links. No file system access, network calls, or command execution capabilities exist.
Risk Factors
🌐 Network access (6)
⚙️ External commands (20)
📁 Filesystem access (4)
Jan 17, 2026, 07:37 AM
This is a pure documentation skill containing only instructional markdown content. No executable code, scripts, or functions exist. Static findings are false positives triggered by documentation patterns: 'sha256' in http_archive() calls are integrity checksums for dependency downloads (security best practice), backticks are Markdown code fences, and URL references are documentation links. No file system access, network calls, or command execution capabilities exist.
Risk Factors
🌐 Network access (6)
⚙️ External commands (20)
📁 Filesystem access (4)
Jan 4, 2026, 04:49 PM
Pure documentation skill with instructional templates for Bazel optimization. No executable code, no file system access, no network calls, no environment variable reading. Contains only markdown documentation and example Bazel configuration patterns.
Jan 4, 2026, 04:49 PM
Pure documentation skill with instructional templates for Bazel optimization. No executable code, no file system access, no network calls, no environment variable reading. Contains only markdown documentation and example Bazel configuration patterns.