Looks like a parser bug (tested with 2.9.1) - I get the same cache file with and without the audit keyword for the exec rule.
That reminds me that we had the same problem with "audit capability" (bug 1378091) - we should probably check _all_ code sections that handle the audit keyword ;-) (or simply create test profiles for each rule type with and without the audit keyword, which might be the faster solution)
Looks like a parser bug (tested with 2.9.1) - I get the same cache file with and without the audit keyword for the exec rule.
That reminds me that we had the same problem with "audit capability" (bug 1378091) - we should probably check _all_ code sections that handle the audit keyword ;-) (or simply create test profiles for each rule type with and without the audit keyword, which might be the faster solution)