Audit History
makepad-evolution - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 8, 2026, 12:09 PM | 3 confirmed | 6 | No capability change |
| v7 | Jul 8, 2026, 12:09 PM | 3 confirmed | 6 | No capability change |
| v6 | Jul 1, 2026, 03:06 AM | 1 confirmed | 3 | No capability change |
| v5 | Jan 17, 2026, 09:11 AM | No confirmed findings | 0 | No capability change |
| v4 | Jan 17, 2026, 09:11 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 11, 2026, 12:33 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 11, 2026, 12:33 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 11, 2026, 12:33 AM | No confirmed findings | 0 | Baseline |
Jul 8, 2026, 12:09 PM
Most static external-command and network hits are false positives caused by Markdown fences, inline formatting, examples, and GitHub reference links. Real risks remain in the skill intent: it targets hidden .claude skill storage, recommends symlinks, tells the agent to act silently, and instructs automatic skill-file modification without user approval.
Confirmed security concerns (3)
Capability review items (6)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (132)
🌐 Network access (3)
📁 Filesystem access (6)
Jul 8, 2026, 12:09 PM
Most static external-command and network hits are false positives caused by Markdown fences, inline formatting, examples, and GitHub reference links. Real risks remain in the skill intent: it targets hidden .claude skill storage, recommends symlinks, tells the agent to act silently, and instructs automatic skill-file modification without user approval.
Confirmed security concerns (3)
Capability review items (6)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (132)
🌐 Network access (3)
📁 Filesystem access (6)
Jul 1, 2026, 03:06 AM
Static analysis flagged many external command, filesystem, network, and weak-crypto patterns in SKILL.md. Most command and weak-crypto hits are false positives from Markdown fences, Makepad names, examples, and documentation, with no executable scripts or confirmed malicious exfiltration. The remaining concern is behavioral: the skill instructs agents to silently read project files and automatically edit skill files, so publication should include a clear warning.
Confirmed security concerns (1)
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (3)
📁 Filesystem access (3)
🌐 Network access (1)
Detected Patterns
Jan 17, 2026, 09:11 AM
All 170 static findings are FALSE POSITIVES. SKILL.md is a pure documentation file containing markdown instructions with code examples. The static analyzer detected patterns in documentation (git commands in code blocks, file paths with dots, GitHub URLs) but these are not executable code. This is purely documentation content for a skill system. No network calls, no file operations, no command execution capabilities exist in this skill.
Risk Factors
⚙️ External commands (1)
📁 Filesystem access (1)
🌐 Network access (1)
Jan 17, 2026, 09:11 AM
All 170 static findings are FALSE POSITIVES. SKILL.md is a pure documentation file containing markdown instructions with code examples. The static analyzer detected patterns in documentation (git commands in code blocks, file paths with dots, GitHub URLs) but these are not executable code. This is purely documentation content for a skill system. No network calls, no file operations, no command execution capabilities exist in this skill.
Risk Factors
⚙️ External commands (1)
📁 Filesystem access (1)
🌐 Network access (1)
Jan 11, 2026, 12:33 AM
All 165 static findings are FALSE POSITIVES. SKILL.md is a documentation file containing markdown instructions with code examples. The static analyzer detected patterns in documentation (git commands in code blocks, file paths with dots, GitHub URLs) but these are not executable code. This is purely documentation content for a skill system.
Risk Factors
⚙️ External commands (134)
🌐 Network access (3)
📁 Filesystem access (6)
Jan 11, 2026, 12:33 AM
All 165 static findings are FALSE POSITIVES. SKILL.md is a documentation file containing markdown instructions with code examples. The static analyzer detected patterns in documentation (git commands in code blocks, file paths with dots, GitHub URLs) but these are not executable code. This is purely documentation content for a skill system.
Risk Factors
⚙️ External commands (134)
🌐 Network access (3)
📁 Filesystem access (6)
Jan 11, 2026, 12:33 AM
All 165 static findings are FALSE POSITIVES. SKILL.md is a documentation file containing markdown instructions with code examples. The static analyzer detected patterns in documentation (git commands in code blocks, file paths with dots, GitHub URLs) but these are not executable code. This is purely documentation content for a skill system.