Audit History
embedding-strategies - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 7, 2026, 07:47 AM | No confirmed findings | 0 | No capability change |
| v8 | Jul 7, 2026, 07:47 AM | No confirmed findings | 0 | External commands |
| v7 | Jul 1, 2026, 12:25 AM | No confirmed findings | 2 | No capability change |
| v6 | Jul 1, 2026, 12:25 AM | No confirmed findings | 2 | Network access |
| v5 | Jan 21, 2026, 07:19 PM | No confirmed findings | 0 | Network accessExternal commands |
| v4 | Jan 17, 2026, 08:42 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 08:42 AM | No confirmed findings | 0 | Network accessExternal commands |
| v2 | Jan 4, 2026, 05:13 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 4, 2026, 05:13 PM | No confirmed findings | 0 | Baseline |
Jul 7, 2026, 07:47 AM
All static detections are false positives caused by Markdown code fences, documentation links, and ordinary variable text. No prompt injection attempt, covert exfiltration intent, command execution, or system reconnaissance behavior was found in SKILL.md.
Risk Factors
⚙️ External commands (11)
🌐 Network access (3)
Jul 7, 2026, 07:47 AM
All static detections are false positives caused by Markdown code fences, documentation links, and ordinary variable text. No prompt injection attempt, covert exfiltration intent, command execution, or system reconnaissance behavior was found in SKILL.md.
Risk Factors
⚙️ External commands (11)
🌐 Network access (3)
Jul 1, 2026, 12:25 AM
Static analysis flagged markdown code fences as Ruby shell backticks, but these are documentation delimiters and not executable shell commands. The hardcoded URLs are reference links to vendor documentation and benchmarks, while sample embedding code may contact model providers only if a user runs it with their own environment.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (4)
Jul 1, 2026, 12:25 AM
Static analysis flagged markdown code fences as Ruby shell backticks, but these are documentation delimiters and not executable shell commands. The hardcoded URLs are reference links to vendor documentation and benchmarks, while sample embedding code may contact model providers only if a user runs it with their own environment.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (4)
Jan 21, 2026, 07:19 PM
All static findings are false positives. C2 keyword alerts triggered by hash hex strings. Weak crypto alerts from hash substrings. External command alerts from ASCII flow diagrams using arrows. Hardcoded URL alerts are legitimate documentation links. No malicious code, command execution, or data exfiltration patterns found.
Jan 17, 2026, 08:42 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
🌐 Network access (3)
Detected Patterns
Jan 17, 2026, 08:42 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
🌐 Network access (3)
Detected Patterns
Jan 4, 2026, 05:13 PM
Pure documentation skill with code templates. No network, file system, or credential access. Contains only educational content about embedding models and strategies.
Jan 4, 2026, 05:13 PM
Pure documentation skill with code templates. No network, file system, or credential access. Contains only educational content about embedding models and strategies.