Audit History
perf-fullstack-engineer - 4 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v4 Latest | Jul 23, 2026, 11:51 PM | No confirmed findings | 0 | External commandsNetwork accessEnv variables |
| v3 | Jul 15, 2026, 03:31 PM | No confirmed findings | 0 | No capability change |
| v2 | Jul 15, 2026, 03:31 PM | No confirmed findings | 0 | No capability change |
| v1 | Jul 15, 2026, 03:31 PM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 11:51 PM
The skill is readable Markdown guidance with no executable package, prompt injection, credential collection, obfuscation, or covert data transfer. Static alerts primarily misread Markdown backticks, Chinese text, placeholders, localhost URLs, and documented developer commands as dangerous behavior.
Risk Factors
⚙️ External commands (45)
🌐 Network access (8)
🔑 Env variables (1)
Jul 15, 2026, 03:31 PM
All static findings are false positives caused by Markdown fences, inline command examples, placeholder URLs, SQL diagnostics, and multilingual text. The skill contains no executable files, automatic command execution, credential access, obfuscation, or prompt injection.
Jul 15, 2026, 03:31 PM
All static findings are false positives caused by Markdown fences, inline command examples, placeholder URLs, SQL diagnostics, and multilingual text. The skill contains no executable files, automatic command execution, credential access, obfuscation, or prompt injection.
Jul 15, 2026, 03:31 PM
All static findings are false positives caused by Markdown fences, inline command examples, placeholder URLs, SQL diagnostics, and multilingual text. The skill contains no executable files, automatic command execution, credential access, obfuscation, or prompt injection.