Audit History
deployment-pipeline-design - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 7, 2026, 07:27 AM | No confirmed findings | 0 | No capability change |
| v7 | Jul 7, 2026, 07:27 AM | No confirmed findings | 0 | No capability change |
| v6 | Jul 1, 2026, 12:09 AM | No confirmed findings | 2 | No capability change |
| v5 | Jul 1, 2026, 12:09 AM | No confirmed findings | 2 | No capability change |
| v4 | Jan 17, 2026, 08:23 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 08:23 AM | No confirmed findings | 0 | Network accessExternal commandsEnv variables |
| v2 | Jan 4, 2026, 05:07 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 4, 2026, 05:07 PM | No confirmed findings | 0 | Baseline |
Jul 7, 2026, 07:27 AM
All static findings resolve to documentation false positives in SKILL.md. The file contains Markdown fences, example URLs, placeholder credential text, and CI/CD shell snippets, but no executable skill code, prompt injection, or malicious intent was found.
Risk Factors
⚙️ External commands (32)
🌐 Network access (3)
🔑 Env variables (1)
Jul 7, 2026, 07:27 AM
All static findings resolve to documentation false positives in SKILL.md. The file contains Markdown fences, example URLs, placeholder credential text, and CI/CD shell snippets, but no executable skill code, prompt injection, or malicious intent was found.
Risk Factors
⚙️ External commands (32)
🌐 Network access (3)
🔑 Env variables (1)
Jul 1, 2026, 12:09 AM
Static analysis flagged many external command, network, environment, and weak-crypto patterns, but review found they are documentation examples inside SKILL.md. No evidence found of executable code, prompt injection, credential exfiltration, or malicious intent. The remaining risk is low because users may adapt deployment examples that include shell commands, URLs, secrets, and environment variables.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (32)
🌐 Network access (3)
🔑 Env variables (1)
Detected Patterns
Jul 1, 2026, 12:09 AM
Static analysis flagged many external command, network, environment, and weak-crypto patterns, but review found they are documentation examples inside SKILL.md. No evidence found of executable code, prompt injection, credential exfiltration, or malicious intent. The remaining risk is low because users may adapt deployment examples that include shell commands, URLs, secrets, and environment variables.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (32)
🌐 Network access (3)
🔑 Env variables (1)
Detected Patterns
Jan 17, 2026, 08:23 AM
Pure documentation skill containing only markdown explanations and YAML/JSON example snippets. All static findings are false positives triggered by example code patterns in documentation. No executable scripts, network calls, filesystem access, or credential handling code exists. The skill is a reference guide for CI/CD architecture patterns.
Risk Factors
🌐 Network access (3)
⚙️ External commands (32)
🔑 Env variables (1)
Jan 17, 2026, 08:23 AM
Pure documentation skill containing only markdown explanations and YAML/JSON example snippets. All static findings are false positives triggered by example code patterns in documentation. No executable scripts, network calls, filesystem access, or credential handling code exists. The skill is a reference guide for CI/CD architecture patterns.
Risk Factors
🌐 Network access (3)
⚙️ External commands (32)
🔑 Env variables (1)
Jan 4, 2026, 05:07 PM
Pure documentation skill containing only markdown explanations and YAML/JSON example snippets. No executable scripts, network calls, file system access, or command execution code. Content describes CI/CD concepts and provides reference patterns only.
Jan 4, 2026, 05:07 PM
Pure documentation skill containing only markdown explanations and YAML/JSON example snippets. No executable scripts, network calls, file system access, or command execution code. Content describes CI/CD concepts and provides reference patterns only.