Audit History
spark-optimization - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 8, 2026, 02:15 PM | No confirmed findings | 0 | No capability change |
| v7 | Jul 8, 2026, 02:15 PM | No confirmed findings | 0 | External commands |
| v6 | Jul 1, 2026, 12:29 AM | No confirmed findings | 2 | No capability change |
| v5 | Jul 1, 2026, 12:29 AM | No confirmed findings | 2 | External commands |
| v4 | Jan 17, 2026, 10:22 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 10:22 AM | No confirmed findings | 0 | Network accessExternal commands |
| v2 | Jan 4, 2026, 04:27 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 4, 2026, 04:27 PM | No confirmed findings | 0 | Baseline |
Jul 8, 2026, 02:15 PM
The static findings are false positives caused by Markdown code fences, Spark example syntax, Spark monitoring APIs, and documentation links. I found no evidence of executable installer code, credential access, command injection, prompt injection, or data exfiltration intent in SKILL.md.
Risk Factors
⚙️ External commands (22)
🌐 Network access (3)
Jul 8, 2026, 02:15 PM
The static findings are false positives caused by Markdown code fences, Spark example syntax, Spark monitoring APIs, and documentation links. I found no evidence of executable installer code, credential access, command injection, prompt injection, or data exfiltration intent in SKILL.md.
Risk Factors
⚙️ External commands (22)
🌐 Network access (3)
Jul 1, 2026, 12:29 AM
Static analysis flagged Markdown code fences, PySpark examples, diagnostic snippets, and documentation links. Review found no executable skill scripts, credential access, command execution, prompt injection, or data exfiltration behavior. Remaining risk is low because the skill contains external documentation links and operational Spark examples users may adapt.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (3)
Jul 1, 2026, 12:29 AM
Static analysis flagged Markdown code fences, PySpark examples, diagnostic snippets, and documentation links. Review found no executable skill scripts, credential access, command execution, prompt injection, or data exfiltration behavior. Remaining risk is low because the skill contains external documentation links and operational Spark examples users may adapt.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (3)
Jan 17, 2026, 10:22 AM
Pure documentation skill containing only markdown content with Apache Spark tuning guidance. No executable code, credential access, network calls, or malicious patterns detected. All 43 static findings are false positives triggered by misidentified Spark terminology.
Risk Factors
🌐 Network access (3)
⚙️ External commands (23)
Jan 17, 2026, 10:22 AM
Pure documentation skill containing only markdown content with Apache Spark tuning guidance. No executable code, credential access, network calls, or malicious patterns detected. All 43 static findings are false positives triggered by misidentified Spark terminology.
Risk Factors
🌐 Network access (3)
⚙️ External commands (23)
Jan 4, 2026, 04:27 PM
Pure documentation skill containing only markdown content with Spark tuning guidance. No executable code, credential access, network calls, or malicious patterns detected.
Jan 4, 2026, 04:27 PM
Pure documentation skill containing only markdown content with Spark tuning guidance. No executable code, credential access, network calls, or malicious patterns detected.