📦

Audit History

risk-metrics-calculation - 8 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v8 LatestJul 8, 2026, 01:34 PM No confirmed findings0No capability change
v7 Jul 8, 2026, 01:34 PM No confirmed findings0No capability change
v6 Jul 1, 2026, 12:48 AM No confirmed findings1No capability change
v5 Jul 1, 2026, 12:48 AM No confirmed findings1No capability change
v4 Jan 17, 2026, 09:44 AM No confirmed findings0No capability change
v3 Jan 17, 2026, 09:44 AM No confirmed findings0Network accessExternal commands
v2 Jan 4, 2026, 04:18 PM No confirmed findings0No capability change
v1 Jan 4, 2026, 04:18 PM No confirmed findings0Baseline

Jul 8, 2026, 01:34 PM

All static findings are false positives from Markdown code fences, reference links, and benign risk-management prose. The skill contains educational Python snippets for portfolio risk metrics, with no evidence of prompt injection, command execution, or suspicious network behavior.

1
Files scanned
556
Lines analyzed
2
Review items
0
False positives ignored
Audited by: codex

Jul 8, 2026, 01:34 PM

All static findings are false positives from Markdown code fences, reference links, and benign risk-management prose. The skill contains educational Python snippets for portfolio risk metrics, with no evidence of prompt injection, command execution, or suspicious network behavior.

1
Files scanned
556
Lines analyzed
2
Review items
0
False positives ignored
Audited by: codex

Jul 1, 2026, 12:48 AM

Static analysis flagged Markdown code fences as Ruby or shell backtick execution, but the cited lines are documentation fences around Python examples, not executable commands. The hardcoded URLs are bibliography and documentation links, and no prompt injection, data exfiltration, or malicious intent was found in SKILL.md.

1
Files scanned
556
Lines analyzed
3
Review items
3
False positives ignored
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Low
Reference Links to External Documentation
The flagged URLs are resource links for books and pyfolio documentation. They are not active network calls, tracking endpoints, or data transfer logic.
The links appear only under a Resources section and are standard reference URLs. No evidence found of automatic fetching or exfiltration.
Static false positives ignored (3)

These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.

Low
Documentation Code Fences Misclassified as Command Execution
The flagged backtick locations are Markdown code fences around Python examples and a time horizon text block. They do not execute commands or request shell access.
Line-numbered review shows these are Markdown fences and Python documentation snippets. No shell command, subprocess call, or user-controlled execution path is present at the cited locations.
Low
Weak Cryptography Finding Is a Financial Acronym False Positive
The static blocker appears to match CVaR in the skill description, but the context is Conditional Value at Risk, not a cryptographic algorithm.
The cited line describes VaR, CVaR, Sharpe, Sortino, and drawdown analysis. This is finance terminology, not cryptographic implementation.
Low
Network Reconnaissance Finding Is Finance Guidance False Positive
The flagged phrase is a best-practice warning about ignoring correlation during stressed markets. It does not describe scanning networks or hosts.
The cited line is in the finance best-practices section and discusses asset correlation. No evidence found of network discovery behavior.
Audited by: codex

Jul 1, 2026, 12:48 AM

Static analysis flagged Markdown code fences as Ruby or shell backtick execution, but the cited lines are documentation fences around Python examples, not executable commands. The hardcoded URLs are bibliography and documentation links, and no prompt injection, data exfiltration, or malicious intent was found in SKILL.md.

1
Files scanned
556
Lines analyzed
3
Review items
3
False positives ignored
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Low
Reference Links to External Documentation
The flagged URLs are resource links for books and pyfolio documentation. They are not active network calls, tracking endpoints, or data transfer logic.
The links appear only under a Resources section and are standard reference URLs. No evidence found of automatic fetching or exfiltration.
Static false positives ignored (3)

These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.

Low
Documentation Code Fences Misclassified as Command Execution
The flagged backtick locations are Markdown code fences around Python examples and a time horizon text block. They do not execute commands or request shell access.
Line-numbered review shows these are Markdown fences and Python documentation snippets. No shell command, subprocess call, or user-controlled execution path is present at the cited locations.
Low
Weak Cryptography Finding Is a Financial Acronym False Positive
The static blocker appears to match CVaR in the skill description, but the context is Conditional Value at Risk, not a cryptographic algorithm.
The cited line describes VaR, CVaR, Sharpe, Sortino, and drawdown analysis. This is finance terminology, not cryptographic implementation.
Low
Network Reconnaissance Finding Is Finance Guidance False Positive
The flagged phrase is a best-practice warning about ignoring correlation during stressed markets. It does not describe scanning networks or hosts.
The cited line is in the finance best-practices section and discusses asset correlation. No evidence found of network discovery behavior.
Audited by: codex

Jan 17, 2026, 09:44 AM

Documentation-only skill containing Python code examples for financial risk metrics. No executable code, file access, or network calls. Pure educational content matching stated purpose. Pre-computed static findings (100/100 risk) are false positives from scanner misidentifying Python f-strings as shell commands and financial abbreviations as cryptographic algorithms.

2
Files scanned
732
Lines analyzed
2
Review items
0
False positives ignored
Audited by: claude

Jan 17, 2026, 09:44 AM

Documentation-only skill containing Python code examples for financial risk metrics. No executable code, file access, or network calls. Pure educational content matching stated purpose. Pre-computed static findings (100/100 risk) are false positives from scanner misidentifying Python f-strings as shell commands and financial abbreviations as cryptographic algorithms.

2
Files scanned
732
Lines analyzed
2
Review items
0
False positives ignored
Audited by: claude

Jan 4, 2026, 04:18 PM

Scanned documentation file with Python code examples for financial risk metrics. No executable code, file access, network calls, or data processing. Pure educational content matching stated purpose.

4
Files scanned
578
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 4, 2026, 04:18 PM

Scanned documentation file with Python code examples for financial risk metrics. No executable code, file access, network calls, or data processing. Pure educational content matching stated purpose.

4
Files scanned
578
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude