📦

Audit History

debugging-strategies - 9 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v9 LatestJul 7, 2026, 07:16 AM No confirmed findings0No capability change
v8 Jul 7, 2026, 07:16 AM No confirmed findings0No capability change
v7 Jun 30, 2026, 10:45 PM No confirmed findings2No capability change
v6 Jun 30, 2026, 10:45 PM No confirmed findings2Contains scriptsExternal commandsNetwork access
v5 Jan 21, 2026, 07:01 PM No confirmed findings0 Network accessContains scriptsExternal commands
v4 Jan 17, 2026, 08:14 AM No confirmed findings0No capability change
v3 Jan 17, 2026, 08:14 AM No confirmed findings0Network accessContains scriptsExternal commands
v2 Jan 5, 2026, 04:58 PM No confirmed findings0No capability change
v1 Jan 5, 2026, 04:58 PM No confirmed findings0Baseline

Jul 7, 2026, 07:16 AM

All static findings appear to be false positives caused by Markdown code fences, language syntax examples, localhost profiling documentation, and ordinary debugging prose. No prompt injection, data exfiltration intent, hidden command execution, or malicious network behavior was found in SKILL.md.

1
Files scanned
528
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex

Jul 7, 2026, 07:16 AM

All static findings appear to be false positives caused by Markdown code fences, language syntax examples, localhost profiling documentation, and ordinary debugging prose. No prompt injection, data exfiltration intent, hidden command execution, or malicious network behavior was found in SKILL.md.

1
Files scanned
528
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex

Jun 30, 2026, 10:45 PM

Static analysis reported dynamic imports, shell backticks, weak crypto, reconnaissance, and a URL, but context shows documentation examples. No executable files or prompt injection were found; low risk remains because the skill teaches command-line debugging workflows.

1
Files scanned
528
Lines analyzed
5
Review items
1
False positives ignored
Capability review items (2)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Low
Command Examples Require User Judgment
The skill includes git bisect, debugger, profiling, and production debugging examples. These are legitimate instructions, but users should review commands before running them.
The cited lines are documentation examples, not executable skill code. The residual risk is user misuse of debugging commands in real environments.
Low
Local Profiling URL Is Benign
The hardcoded URL points to localhost pprof documentation. No evidence found of external network access, data exfiltration, or remote callback behavior.
The URL is localhost and appears in a Go profiling example. It does not contact a third-party service or transmit data.
Static false positives ignored (1)

These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.

Low
Static Analyzer False Positives in Markdown
The shell backtick and weak crypto hits are caused by markdown code fences, prose, or ordinary identifiers. No evidence found of actual shell execution or cryptographic code.
The locations are inside fenced documentation blocks or normal TypeScript examples. There is no runtime wrapper that executes this content.
Audited by: codex

Jun 30, 2026, 10:45 PM

Static analysis reported dynamic imports, shell backticks, weak crypto, reconnaissance, and a URL, but context shows documentation examples. No executable files or prompt injection were found; low risk remains because the skill teaches command-line debugging workflows.

1
Files scanned
528
Lines analyzed
5
Review items
1
False positives ignored
Capability review items (2)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Low
Command Examples Require User Judgment
The skill includes git bisect, debugger, profiling, and production debugging examples. These are legitimate instructions, but users should review commands before running them.
The cited lines are documentation examples, not executable skill code. The residual risk is user misuse of debugging commands in real environments.
Low
Local Profiling URL Is Benign
The hardcoded URL points to localhost pprof documentation. No evidence found of external network access, data exfiltration, or remote callback behavior.
The URL is localhost and appears in a Go profiling example. It does not contact a third-party service or transmit data.
Static false positives ignored (1)

These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.

Low
Static Analyzer False Positives in Markdown
The shell backtick and weak crypto hits are caused by markdown code fences, prose, or ordinary identifiers. No evidence found of actual shell execution or cryptographic code.
The locations are inside fenced documentation blocks or normal TypeScript examples. There is no runtime wrapper that executes this content.
Audited by: codex

Jan 21, 2026, 07:01 PM

Static analysis detected 54 potential issues, all confirmed as false positives. The 'scripts' patterns are Go import statements in code examples. 'External_commands' are markdown backticks used for code formatting. 'Weak cryptographic algorithm' flags are triggered by Go standard library package names (crypto/pprof). 'Network' URLs are GitHub source URLs and localhost debugging endpoints. All findings are legitimate documentation content with no security concerns.

2
Files scanned
1,137
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 17, 2026, 08:14 AM

AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.

2
Files scanned
705
Lines analyzed
3
Review items
0
False positives ignored

Detected Patterns

Hardcoded URLWeak cryptographic algorithmDynamic import() expressionRuby/shell backtick executionSystem reconnaissance
Audited by: claude

Jan 17, 2026, 08:14 AM

AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.

2
Files scanned
705
Lines analyzed
3
Review items
0
False positives ignored

Detected Patterns

Hardcoded URLWeak cryptographic algorithmDynamic import() expressionRuby/shell backtick executionSystem reconnaissance
Audited by: claude

Jan 5, 2026, 04:58 PM

Pure prompt-based documentation skill with no executable code. Contains only debugging strategy guidance and educational code examples. No scripts, network calls, filesystem access, or command execution capabilities.

4
Files scanned
646
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 5, 2026, 04:58 PM

Pure prompt-based documentation skill with no executable code. Contains only debugging strategy guidance and educational code examples. No scripts, network calls, filesystem access, or command execution capabilities.

4
Files scanned
646
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude