Audit History
risk-metrics-calculation - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 8, 2026, 01:34 PM | No confirmed findings | 0 | No capability change |
| v7 | Jul 8, 2026, 01:34 PM | No confirmed findings | 0 | No capability change |
| v6 | Jul 1, 2026, 12:48 AM | No confirmed findings | 1 | No capability change |
| v5 | Jul 1, 2026, 12:48 AM | No confirmed findings | 1 | No capability change |
| v4 | Jan 17, 2026, 09:44 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 09:44 AM | No confirmed findings | 0 | Network accessExternal commands |
| v2 | Jan 4, 2026, 04:18 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 4, 2026, 04:18 PM | No confirmed findings | 0 | Baseline |
Jul 8, 2026, 01:34 PM
All static findings are false positives from Markdown code fences, reference links, and benign risk-management prose. The skill contains educational Python snippets for portfolio risk metrics, with no evidence of prompt injection, command execution, or suspicious network behavior.
Risk Factors
⚙️ External commands (11)
🌐 Network access (3)
Jul 8, 2026, 01:34 PM
All static findings are false positives from Markdown code fences, reference links, and benign risk-management prose. The skill contains educational Python snippets for portfolio risk metrics, with no evidence of prompt injection, command execution, or suspicious network behavior.
Risk Factors
⚙️ External commands (11)
🌐 Network access (3)
Jul 1, 2026, 12:48 AM
Static analysis flagged Markdown code fences as Ruby or shell backtick execution, but the cited lines are documentation fences around Python examples, not executable commands. The hardcoded URLs are bibliography and documentation links, and no prompt injection, data exfiltration, or malicious intent was found in SKILL.md.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (7)
🌐 Network access (3)
Jul 1, 2026, 12:48 AM
Static analysis flagged Markdown code fences as Ruby or shell backtick execution, but the cited lines are documentation fences around Python examples, not executable commands. The hardcoded URLs are bibliography and documentation links, and no prompt injection, data exfiltration, or malicious intent was found in SKILL.md.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (7)
🌐 Network access (3)
Jan 17, 2026, 09:44 AM
Documentation-only skill containing Python code examples for financial risk metrics. No executable code, file access, or network calls. Pure educational content matching stated purpose. Pre-computed static findings (100/100 risk) are false positives from scanner misidentifying Python f-strings as shell commands and financial abbreviations as cryptographic algorithms.
Risk Factors
🌐 Network access (3)
Jan 17, 2026, 09:44 AM
Documentation-only skill containing Python code examples for financial risk metrics. No executable code, file access, or network calls. Pure educational content matching stated purpose. Pre-computed static findings (100/100 risk) are false positives from scanner misidentifying Python f-strings as shell commands and financial abbreviations as cryptographic algorithms.
Risk Factors
🌐 Network access (3)
Jan 4, 2026, 04:18 PM
Scanned documentation file with Python code examples for financial risk metrics. No executable code, file access, network calls, or data processing. Pure educational content matching stated purpose.
Jan 4, 2026, 04:18 PM
Scanned documentation file with Python code examples for financial risk metrics. No executable code, file access, network calls, or data processing. Pure educational content matching stated purpose.