Audit History
monorepo-management - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 8, 2026, 12:30 PM | No confirmed findings | 0 | No capability change |
| v7 | Jul 8, 2026, 12:30 PM | No confirmed findings | 0 | No capability change |
| v6 | Jul 1, 2026, 12:51 AM | No confirmed findings | 3 | No capability change |
| v5 | Jul 1, 2026, 12:51 AM | No confirmed findings | 3 | No capability change |
| v4 | Jan 17, 2026, 08:29 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 08:29 AM | No confirmed findings | 0 | Network accessExternal commandsFilesystem accessEnv variables |
| v2 | Jan 4, 2026, 04:43 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 4, 2026, 04:43 PM | No confirmed findings | 0 | Baseline |
Jul 8, 2026, 12:30 PM
The static findings are false positives caused by Markdown code fences, example configuration paths, and standard CI secret placeholders. No executable skill code, prompt injection, credential exfiltration, or malicious intent was found in SKILL.md.
Risk Factors
⚙️ External commands (44)
🌐 Network access (1)
📁 Filesystem access (5)
🔑 Env variables (1)
Jul 8, 2026, 12:30 PM
The static findings are false positives caused by Markdown code fences, example configuration paths, and standard CI secret placeholders. No executable skill code, prompt injection, credential exfiltration, or malicious intent was found in SKILL.md.
Risk Factors
⚙️ External commands (44)
🌐 Network access (1)
📁 Filesystem access (5)
🔑 Env variables (1)
Jul 1, 2026, 12:51 AM
Static analysis flagged command execution, hidden file access, token references, a hardcoded URL, and heuristic combinations. Review found SKILL.md is documentation with fenced examples for Turborepo, Nx, pnpm, CI, and releases; no prompt injection, obfuscated code, secret exfiltration, or executable skill scripts were found. Low risk remains because users may copy commands that install packages, remove node_modules, deploy, or publish packages.
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (8)
🌐 Network access (1)
📁 Filesystem access (5)
🔑 Env variables (1)
Jul 1, 2026, 12:51 AM
Static analysis flagged command execution, hidden file access, token references, a hardcoded URL, and heuristic combinations. Review found SKILL.md is documentation with fenced examples for Turborepo, Nx, pnpm, CI, and releases; no prompt injection, obfuscated code, secret exfiltration, or executable skill scripts were found. Low risk remains because users may copy commands that install packages, remove node_modules, deploy, or publish packages.
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (8)
🌐 Network access (1)
📁 Filesystem access (5)
🔑 Env variables (1)
Jan 17, 2026, 08:29 AM
This skill contains purely educational documentation about monorepo tools. The SKILL.md file contains only instructional text, example commands, and configuration samples. No executable code, network calls, filesystem operations, or credential access exist. All static findings are FALSE POSITIVES caused by misidentifying bash code examples and JSON schema URLs as security-relevant patterns.
Risk Factors
🌐 Network access (1)
⚙️ External commands (44)
📁 Filesystem access (5)
🔑 Env variables (2)
Jan 17, 2026, 08:29 AM
This skill contains purely educational documentation about monorepo tools. The SKILL.md file contains only instructional text, example commands, and configuration samples. No executable code, network calls, filesystem operations, or credential access exist. All static findings are FALSE POSITIVES caused by misidentifying bash code examples and JSON schema URLs as security-relevant patterns.
Risk Factors
🌐 Network access (1)
⚙️ External commands (44)
📁 Filesystem access (5)
🔑 Env variables (2)
Jan 4, 2026, 04:43 PM
All files contain only instructional text with example commands and configurations. No executable scripts, network calls, filesystem access, or environment access are present. This is purely educational content.
Jan 4, 2026, 04:43 PM
All files contain only instructional text with example commands and configurations. No executable scripts, network calls, filesystem access, or environment access are present. This is purely educational content.