Audit History
dispatching-parallel-agents - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 8, 2026, 12:39 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 8, 2026, 12:39 PM | No confirmed findings | 0 | External commands |
| v3 | Jul 1, 2026, 03:25 AM | No confirmed findings | 0 | No capability change |
| v2 | Jul 1, 2026, 03:25 AM | No confirmed findings | 0 | External commands |
| v1 | Feb 24, 2026, 09:37 AM | No confirmed findings | 0 | Baseline |
Jul 8, 2026, 12:39 PM
All static detections were false positives caused by Markdown code fences and ordinary checklist language. The skill is documentation for coordinating independent AI agents and contains no executable scripts, network calls, data exfiltration intent, or prompt injection content.
Risk Factors
⚙️ External commands (7)
Jul 8, 2026, 12:39 PM
All static detections were false positives caused by Markdown code fences and ordinary checklist language. The skill is documentation for coordinating independent AI agents and contains no executable scripts, network calls, data exfiltration intent, or prompt injection content.
Risk Factors
⚙️ External commands (7)
Jul 1, 2026, 03:25 AM
Static analysis flagged Markdown code fences, prose, and task examples as command execution, weak cryptography, and reconnaissance. Manual review found no executable script, no network access, no filesystem access, and no prompt injection attempt.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Jul 1, 2026, 03:25 AM
Static analysis flagged Markdown code fences, prose, and task examples as command execution, weak cryptography, and reconnaissance. Manual review found no executable script, no network access, no filesystem access, and no prompt injection attempt.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Feb 24, 2026, 09:37 AM
This skill is a documentation-only markdown file providing guidance on parallel agent dispatching patterns. Static analyzer flagged 10 patterns as potential risks, but all are FALSE POSITIVES. The external_commands detections are documentation code examples (not executable). The cryptographic and reconnaissance flags reference documentation text with no actual security-relevant operations. No executable code, network access, file system operations, or sensitive data handling present.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.