Audit History
on-call-handoff-patterns - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 8, 2026, 12:54 PM | 1 confirmed | 1 | No capability change |
| v6 | Jul 8, 2026, 12:54 PM | 1 confirmed | 1 | No capability change |
| v5 | Jul 1, 2026, 01:10 AM | No confirmed findings | 0 | No capability change |
| v4 | Jan 17, 2026, 08:57 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 08:57 AM | No confirmed findings | 0 | Network accessExternal commands |
| v2 | Jan 4, 2026, 04:51 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 4, 2026, 04:51 PM | No confirmed findings | 0 | Baseline |
Jul 8, 2026, 12:54 PM
Most static findings are false positives from markdown fences, documentation links, and ordinary checklist language. One real issue remains: the quick reference includes a destructive Redis FLUSHDB command that can delete data if copied or executed without review. No prompt injection or data exfiltration intent was found.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (20)
Jul 8, 2026, 12:54 PM
Most static findings are false positives from markdown fences, documentation links, and ordinary checklist language. One real issue remains: the quick reference includes a destructive Redis FLUSHDB command that can delete data if copied or executed without review. No prompt injection or data exfiltration intent was found.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (20)
Jul 1, 2026, 01:10 AM
Static analysis reported command execution, network, weak cryptography, scheduling, and reconnaissance patterns in SKILL.md. AI review found these are documentation examples, Markdown fences, timestamps, operational checklist text, and reference links, with no executable code, prompt injection, data exfiltration, or malicious intent.
Static false positives ignored (5)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (20)
Jan 17, 2026, 08:57 AM
Pure documentation skill containing only static markdown templates and JSON metadata. No executable code, network calls, file access, or environment variable reads. Content matches stated purpose of on-call shift handoffs.
Risk Factors
🌐 Network access (13)
⚙️ External commands (20)
Jan 17, 2026, 08:57 AM
Pure documentation skill containing only static markdown templates and JSON metadata. No executable code, network calls, file access, or environment variable reads. Content matches stated purpose of on-call shift handoffs.
Risk Factors
🌐 Network access (13)
⚙️ External commands (20)
Jan 4, 2026, 04:51 PM
Pure documentation skill containing only static markdown templates and JSON metadata. No executable code, network calls, file access, or environment variable reads. Content matches stated purpose.
Jan 4, 2026, 04:51 PM
Pure documentation skill containing only static markdown templates and JSON metadata. No executable code, network calls, file access, or environment variable reads. Content matches stated purpose.