Audit History
rag-implementation - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 8, 2026, 01:13 PM | No confirmed findings | 0 | No capability change |
| v6 | Jul 8, 2026, 01:13 PM | No confirmed findings | 0 | External commandsEnv variables |
| v5 | Jul 1, 2026, 12:31 AM | 1 confirmed | 1 | External commandsEnv variables |
| v4 | Jan 17, 2026, 09:35 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 09:35 AM | No confirmed findings | 0 | External commandsEnv variables Filesystem access |
| v2 | Jan 4, 2026, 05:03 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 4, 2026, 05:03 PM | No confirmed findings | 0 | Baseline |
Jul 8, 2026, 01:13 PM
The static findings are false positives caused by Markdown code fences and illustrative RAG configuration examples. I found no prompt injection, credential exfiltration, autonomous network activity, or executable installer behavior.
Risk Factors
⚙️ External commands (37)
🌐 Network access (1)
🔑 Env variables (1)
Jul 8, 2026, 01:13 PM
The static findings are false positives caused by Markdown code fences and illustrative RAG configuration examples. I found no prompt injection, credential exfiltration, autonomous network activity, or executable installer behavior.
Risk Factors
⚙️ External commands (37)
🌐 Network access (1)
🔑 Env variables (1)
Jul 1, 2026, 12:31 AM
Static analysis reported many high-risk patterns, but review found they are Markdown documentation examples rather than executable skill code. The Ruby backtick findings are false positives caused by fenced Python code blocks. The remaining concerns are low-risk instructional examples that mention a placeholder API key and a localhost vector database URL.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (1)
Jan 17, 2026, 09:35 AM
This is a documentation-only skill containing Markdown guides with Python code examples. No executable scripts, network calls, or file access capabilities exist in the skill itself. All static findings are false positives from the scanner misinterpreting documentation patterns as security risks. Code examples demonstrate typical RAG patterns using LangChain APIs. No obfuscation, persistence mechanisms, or malicious patterns detected.
Risk Factors
🌐 Network access (1)
⚙️ External commands (37)
🔑 Env variables (1)
Jan 17, 2026, 09:35 AM
This is a documentation-only skill containing Markdown guides with Python code examples. No executable scripts, network calls, or file access capabilities exist in the skill itself. All static findings are false positives from the scanner misinterpreting documentation patterns as security risks. Code examples demonstrate typical RAG patterns using LangChain APIs. No obfuscation, persistence mechanisms, or malicious patterns detected.
Risk Factors
🌐 Network access (1)
⚙️ External commands (37)
🔑 Env variables (1)
Jan 4, 2026, 05:03 PM
This is a documentation-only skill containing Markdown guides with Python code examples. No executable scripts, no network calls, and no file access capabilities exist in the skill itself. The code examples demonstrate typical RAG patterns using LangChain APIs. No obfuscation, persistence mechanisms, or malicious patterns detected.
Risk Factors
📁 Filesystem access (1)
🌐 Network access (1)
Jan 4, 2026, 05:03 PM
This is a documentation-only skill containing Markdown guides with Python code examples. No executable scripts, no network calls, and no file access capabilities exist in the skill itself. The code examples demonstrate typical RAG patterns using LangChain APIs. No obfuscation, persistence mechanisms, or malicious patterns detected.