Audit History
saga-orchestration - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 8, 2026, 01:41 PM | No confirmed findings | 0 | No capability change |
| v6 | Jul 8, 2026, 01:41 PM | No confirmed findings | 0 | External commandsNetwork access |
| v5 | Jul 1, 2026, 12:53 AM | No confirmed findings | 0 | Network accessExternal commands |
| v4 | Jan 17, 2026, 09:54 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 09:54 AM | No confirmed findings | 0 | Network accessExternal commands |
| v2 | Jan 4, 2026, 04:19 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 4, 2026, 04:19 PM | No confirmed findings | 0 | Baseline |
Jul 8, 2026, 01:41 PM
The static findings are false positives caused by Markdown code fences, reference links, and a normal Python uuid import. No prompt injection, data exfiltration intent, executable installer script, or malicious behavior was found in SKILL.md.
Risk Factors
⚙️ External commands (9)
🌐 Network access (2)
Jul 8, 2026, 01:41 PM
The static findings are false positives caused by Markdown code fences, reference links, and a normal Python uuid import. No prompt injection, data exfiltration intent, executable installer script, or malicious behavior was found in SKILL.md.
Risk Factors
⚙️ External commands (9)
🌐 Network access (2)
Jul 1, 2026, 12:53 AM
Static analysis reported shell execution, network, blocker, weak crypto, and reconnaissance patterns. Manual review found these are false positives from markdown code fences, architecture diagram text, an import in sample code, best-practice prose, and two documentation links. No evidence found of malicious intent, prompt injection, data exfiltration, executable setup logic, or runtime network behavior.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Jan 17, 2026, 09:54 AM
Pure documentation skill containing code templates for saga pattern implementation. Contains no executable code, filesystem access, network calls, or command execution. All static findings are false positives triggered by documentation text containing technical terminology that scanners incorrectly flag as cryptographic terms, C2 indicators, or shell commands.
Risk Factors
🌐 Network access (2)
Jan 17, 2026, 09:54 AM
Pure documentation skill containing code templates for saga pattern implementation. Contains no executable code, filesystem access, network calls, or command execution. All static findings are false positives triggered by documentation text containing technical terminology that scanners incorrectly flag as cryptographic terms, C2 indicators, or shell commands.
Risk Factors
🌐 Network access (2)
Jan 4, 2026, 04:19 PM
Pure documentation skill with code templates only. No filesystem access, network calls, command execution, or data collection capabilities detected. All code examples are educational templates for implementing saga patterns.
Jan 4, 2026, 04:19 PM
Pure documentation skill with code templates only. No filesystem access, network calls, command execution, or data collection capabilities detected. All code examples are educational templates for implementing saga patterns.