Audit History
event-store-design - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 7, 2026, 07:58 AM | No confirmed findings | 0 | No capability change |
| v6 | Jul 7, 2026, 07:58 AM | No confirmed findings | 0 | External commands |
| v5 | Jul 1, 2026, 12:33 AM | 2 confirmed | 1 | External commands |
| v4 | Jan 17, 2026, 08:51 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 08:51 AM | No confirmed findings | 0 | Network accessExternal commands |
| v2 | Jan 4, 2026, 04:19 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 4, 2026, 04:19 PM | No confirmed findings | 0 | Baseline |
Jul 7, 2026, 07:58 AM
All static findings appear to be false positives from Markdown fences, database query examples, resource links, and event-store schema terms. No prompt injection, exfiltration intent, or malicious behavior was found in SKILL.md.
Risk Factors
⚙️ External commands (10)
🌐 Network access (5)
Jul 7, 2026, 07:58 AM
All static findings appear to be false positives from Markdown fences, database query examples, resource links, and event-store schema terms. No prompt injection, exfiltration intent, or malicious behavior was found in SKILL.md.
Risk Factors
⚙️ External commands (10)
🌐 Network access (5)
Jul 1, 2026, 12:33 AM
AI review downgraded the static risk score after checking SKILL.md. The backtick, weak cryptography, reconnaissance, and fetch detections are false positives from markdown fences, documentation text, schema examples, database calls, and public reference links. One medium issue remains because the EventStoreDB example disables TLS for a localhost URI, which needs a publication warning for production use.
Confirmed security concerns (2)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (3)
Detected Patterns
Jan 17, 2026, 08:51 AM
Documentation-only skill containing architectural guidance, technology comparisons, and code templates for event store design. No executable code, scripts, network calls, or external command execution. Static findings are false positives: C2 flag from GitHub URL, cryptographic flags from ASCII diagram characters, shell backticks from SQL identifiers.
Risk Factors
🌐 Network access (5)
Jan 17, 2026, 08:51 AM
Documentation-only skill containing architectural guidance, technology comparisons, and code templates for event store design. No executable code, scripts, network calls, or external command execution. Static findings are false positives: C2 flag from GitHub URL, cryptographic flags from ASCII diagram characters, shell backticks from SQL identifiers.
Risk Factors
🌐 Network access (5)
Jan 4, 2026, 04:19 PM
Documentation-only skill with no executable code. The SKILL.md file contains architectural guidance, technology comparisons, and code templates. No scripts, network calls, filesystem access, environment variable reads, or external command execution.
Jan 4, 2026, 04:19 PM
Documentation-only skill with no executable code. The SKILL.md file contains architectural guidance, technology comparisons, and code templates. No scripts, network calls, filesystem access, environment variable reads, or external command execution.