Audit History
hybrid-search-implementation - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 7, 2026, 07:28 AM | 1 confirmed | 0 | No capability change |
| v7 | Jul 7, 2026, 07:28 AM | 1 confirmed | 0 | External commands |
| v6 | Jul 1, 2026, 01:11 AM | 1 confirmed | 1 | Network access Contains scriptsFilesystem access |
| v5 | Jan 21, 2026, 07:22 PM | No confirmed findings | 0 | Contains scriptsFilesystem access Network accessExternal commands |
| v4 | Jan 17, 2026, 09:23 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 09:23 AM | No confirmed findings | 0 | External commands |
| v2 | Jan 4, 2026, 04:30 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 4, 2026, 04:30 PM | No confirmed findings | 0 | Baseline |
Jul 7, 2026, 07:28 AM
Most static findings are false positives from Markdown code fences, search variable names, and documentation links. No prompt injection, credential access, or malicious execution intent was found. One semantic issue remains in the PostgreSQL metadata filter example, which can permit SQL injection if filter names are untrusted.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (9)
🌐 Network access (4)
Jul 7, 2026, 07:28 AM
Most static findings are false positives from Markdown code fences, search variable names, and documentation links. No prompt injection, credential access, or malicious execution intent was found. One semantic issue remains in the PostgreSQL metadata filter example, which can permit SQL injection if filter names are untrusted.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (9)
🌐 Network access (4)
Jul 1, 2026, 01:11 AM
Most static findings are false positives caused by Markdown code fences, search terminology, and resource links. The audit found a real SQL injection risk in the PostgreSQL template, where metadata keys are interpolated into SQL, so publication should wait for a safer example.
Confirmed security concerns (1)
Needs review findings (1)
These findings came from uncertain legacy audit verdicts, so they require review but are not counted as confirmed security issues.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (3)
Detected Patterns
Jan 21, 2026, 07:22 PM
All static findings are false positives. The skill contains documentation templates for hybrid search algorithms (RRF, linear fusion) with PostgreSQL, Elasticsearch, and custom RAG pipelines. Static scanner misidentified mathematical formulas as crypto operations, markdown code fences as command execution, and benign terminology as security risks. No malicious code or credential exfiltration present.
Risk Factors
⚡ Contains scripts (1)
📁 Filesystem access (1)
Jan 17, 2026, 09:23 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
🌐 Network access (4)
Detected Patterns
Jan 17, 2026, 09:23 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
🌐 Network access (4)
Detected Patterns
Jan 4, 2026, 04:30 PM
Documentation-only skill with Python templates for hybrid search. Templates show database connections (PostgreSQL, Elasticsearch) which implies network access in user implementations. No credential access, file system writes, or command execution. Risk is limited to standard template patterns.
Risk Factors
🌐 Network access (2)
Jan 4, 2026, 04:30 PM
Documentation-only skill with Python templates for hybrid search. Templates show database connections (PostgreSQL, Elasticsearch) which implies network access in user implementations. No credential access, file system writes, or command execution. Risk is limited to standard template patterns.