Skills pci-compliance Audit History
📦

Audit History

pci-compliance - 8 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v8 LatestJul 8, 2026, 01:05 PM No confirmed findings0No capability change
v7 Jul 8, 2026, 01:05 PM No confirmed findings0External commandsEnv variables
v6 Jul 1, 2026, 01:19 AM 1 confirmed0No capability change
v5 Jan 21, 2026, 07:45 PM No confirmed findings0 External commandsEnv variables
v4 Jan 17, 2026, 09:05 AM No confirmed findings0No capability change
v3 Jan 17, 2026, 09:05 AM No confirmed findings0External commandsEnv variables
v2 Jan 4, 2026, 04:53 PM No confirmed findings0No capability change
v1 Jan 4, 2026, 04:53 PM No confirmed findings0Baseline

Jul 8, 2026, 01:05 PM

The detected command, secret, key-file, and reconnaissance patterns are false positives caused by Markdown code fences and PCI documentation examples. No prompt injection text, data exfiltration intent, or bundled credential material was found in SKILL.md.

1
Files scanned
467
Lines analyzed
2
Review items
0
False positives ignored
Audited by: codex

Jul 8, 2026, 01:05 PM

The detected command, secret, key-file, and reconnaissance patterns are false positives caused by Markdown code fences and PCI documentation examples. No prompt injection text, data exfiltration intent, or bundled credential material was found in SKILL.md.

1
Files scanned
467
Lines analyzed
2
Review items
0
False positives ignored
Audited by: codex

Jul 1, 2026, 01:19 AM

Static findings were reviewed against SKILL.md context. The reported command execution, sensitive-file, weak-crypto, reconnaissance, and Windows SAM matches are false positives caused by Markdown fences, PCI terminology, cookie settings, resource names, and defensive examples; no prompt injection or malicious behavior was found. A low-risk documentation concern remains because examples include placeholder payment secrets and card data that should not be copied into production.

1
Files scanned
467
Lines analyzed
1
Review items
2
False positives ignored

Confirmed security concerns (1)

Low
Illustrative Payment Secrets and Card Data
The skill includes sample Stripe key and card values for demonstration. They appear to be placeholders and test data, but users could copy the pattern into production code instead of using managed secret storage and hosted collection.
The values are clearly shown inside instructional examples, not active code in this package. The risk is documentation misuse rather than credential theft or code execution.
Static false positives ignored (2)

These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.

Low
Static Command Execution Findings Dismissed
The external command detections correspond to Markdown code fences around Python examples. No Ruby backtick execution, shell execution, subprocess invocation, or user-controlled command construction was found in SKILL.md.
The flagged locations are fenced documentation examples. There is no executable script file in the reported file structure.
Low
Static Sensitive and Reconnaissance Findings Dismissed
The sensitive-file, Windows SAM, weak-crypto, system reconnaissance, and network reconnaissance alerts are false positives. They match PCI guidance terms, encryption key variables, cookie attributes, resource names, and defensive checklist language.
The reviewed lines are compliance guidance and safe configuration examples. No evidence found of protected file access, host probing, network scanning, or weak cryptographic implementation.
Audited by: codex

Jan 21, 2026, 07:45 PM

Educational PCI DSS compliance skill. All static findings are false positives. The skill provides documentation and code examples for implementing payment card security requirements. No actual vulnerable code or malicious patterns present.

2
Files scanned
935
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 17, 2026, 09:05 AM

AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.

2
Files scanned
644
Lines analyzed
2
Review items
0
False positives ignored

Detected Patterns

Weak cryptographic algorithmSystem reconnaissanceRuby/shell backtick executionGeneric API/secret keysCertificate/key filesWindows SAM databaseNetwork reconnaissance[HEURISTIC] DANGEROUS COMBINATION: Code execution + Network + Credential access
Audited by: claude

Jan 17, 2026, 09:05 AM

AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.

2
Files scanned
644
Lines analyzed
2
Review items
0
False positives ignored

Detected Patterns

Weak cryptographic algorithmSystem reconnaissanceRuby/shell backtick executionGeneric API/secret keysCertificate/key filesWindows SAM databaseNetwork reconnaissance[HEURISTIC] DANGEROUS COMBINATION: Code execution + Network + Credential access
Audited by: claude

Jan 4, 2026, 04:53 PM

Pure documentation skill containing only educational content about PCI DSS compliance. No executable scripts, filesystem access, environment access, network calls, or code execution capabilities exist. All code snippets are illustrative examples within markdown documentation.

4
Files scanned
688
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 4, 2026, 04:53 PM

Pure documentation skill containing only educational content about PCI DSS compliance. No executable scripts, filesystem access, environment access, network calls, or code execution capabilities exist. All code snippets are illustrative examples within markdown documentation.

4
Files scanned
688
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude