πŸ“¦

Audit History

conversion-signal-qa - 7 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v7 Latest26 июл. 2026 г., 10:07 No confirmed findings0No capability change
v6 26 июл. 2026 г., 10:07 No confirmed findings0No capability change
v5 13 июл. 2026 г., 12:44 No confirmed findings0No capability change
v4 13 июл. 2026 г., 12:44 No confirmed findings0No capability change
v3 12 июл. 2026 г., 11:46 No confirmed findings0No capability change
v2 6 июл. 2026 г., 16:25 No confirmed findings0No capability change
v1 4 июл. 2026 г., 16:05 1 confirmed0Baseline

26 июл. 2026 г., 10:07

All 39 static findings are false positives caused by Markdown formatting, relative documentation links, and marketing terminology. The skill contains no executable commands, network requests, path traversal behavior, prompt-injection language, or evidence of data exfiltration. It explicitly treats pasted exports as untrusted and requires consent before saving results.

3
Files scanned
167
Lines analyzed
3
Review items
0
False positives ignored
Audited by: claude

26 июл. 2026 г., 10:07

All 39 static findings are false positives caused by Markdown formatting, relative documentation links, and marketing terminology. The skill contains no executable commands, network requests, path traversal behavior, prompt-injection language, or evidence of data exfiltration. It explicitly treats pasted exports as untrusted and requires consent before saving results.

3
Files scanned
167
Lines analyzed
3
Review items
0
False positives ignored
Audited by: claude

13 июл. 2026 г., 12:44

All 39 static findings are false positives caused by Markdown links, code fences, inline code, slash-separated labels, or repository metadata. The skill contains no executable commands, network requests, path traversal operations, reconnaissance behavior, or prompt injection.

3
Files scanned
167
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex

13 июл. 2026 г., 12:44

ВсС 39 статичСских Π½Π°Ρ…ΠΎΠ΄ΠΎΠΊ ΡΠ²Π»ΡΡŽΡ‚ΡΡ Π»ΠΎΠΆΠ½Ρ‹ΠΌΠΈ срабатываниями, Π²Ρ‹Π·Π²Π°Π½Π½Ρ‹ΠΌΠΈ ссылками Markdown, Π±Π»ΠΎΠΊΠ°ΠΌΠΈ ΠΊΠΎΠ΄Π°, встроСнным ΠΊΠΎΠ΄ΠΎΠΌ, ΠΌΠ΅Ρ‚ΠΊΠ°ΠΌΠΈ с раздСлитСлями-слСшами ΠΈΠ»ΠΈ ΠΌΠ΅Ρ‚Π°Π΄Π°Π½Π½Ρ‹ΠΌΠΈ рСпозитория. Навык Π½Π΅ содСрТит исполняСмых ΠΊΠΎΠΌΠ°Π½Π΄, сСтСвых запросов, ΠΎΠΏΠ΅Ρ€Π°Ρ†ΠΈΠΉ ΠΎΠ±Ρ…ΠΎΠ΄Π° ΠΏΡƒΡ‚Π΅ΠΉ, повСдСния Ρ€Π°Π·Π²Π΅Π΄ΠΊΠΈ ΠΈΠ»ΠΈ ΠΈΠ½ΡŠΠ΅ΠΊΡ†ΠΈΠΉ ΠΏΡ€ΠΎΠΌΠΏΡ‚ΠΎΠ².

3
Files scanned
167
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex

12 июл. 2026 г., 11:46

ВсС 39 статичСских Π½Π°Ρ…ΠΎΠ΄ΠΎΠΊ ΡΠ²Π»ΡΡŽΡ‚ΡΡ Π»ΠΎΠΆΠ½Ρ‹ΠΌΠΈ срабатываниями, Π²Ρ‹Π·Π²Π°Π½Π½Ρ‹ΠΌΠΈ Ρ„ΠΎΡ€ΠΌΠ°Ρ‚ΠΈΡ€ΠΎΠ²Π°Π½ΠΈΠ΅ΠΌ Markdown, ΠΎΡ‚Π½ΠΎΡΠΈΡ‚Π΅Π»ΡŒΠ½Ρ‹ΠΌΠΈ ссылками Π½Π° Π΄ΠΎΠΊΡƒΠΌΠ΅Π½Ρ‚Π°Ρ†ΠΈΡŽ, ΠΌΠ°Ρ€ΠΊΠ΅Ρ‚ΠΈΠ½Π³ΠΎΠ²ΠΎΠΉ Ρ‚Π΅Ρ€ΠΌΠΈΠ½ΠΎΠ»ΠΎΠ³ΠΈΠ΅ΠΉ ΠΈ ΠΌΠ΅Ρ‚Π°Π΄Π°Π½Π½Ρ‹ΠΌΠΈ Π³Π»Π°Π²Π½ΠΎΠΉ страницы. Навык Π½Π΅ содСрТит исполняСмого ΠΊΠΎΠ΄Π°, сСтСвых запросов, ΠΈΠ½ΡŠΠ΅ΠΊΡ†ΠΈΠΉ ΠΏΡ€ΠΎΠΌΠΏΡ‚ΠΎΠ² ΠΈΠ»ΠΈ нСбСзопасной ΠΎΠ±Ρ€Π°Π±ΠΎΡ‚ΠΊΠΈ ΠΏΡƒΡ‚Π΅ΠΉ, Π° ΠΏΠ΅Ρ€Π΅Π΄ сохранСниСм Ρ€Π΅Π·ΡƒΠ»ΡŒΡ‚Π°Ρ‚ΠΎΠ² трСбуСтся согласиС.

3
Files scanned
167
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex

6 июл. 2026 г., 16:25

No confirmed malicious behavior was found. Static findings are false positives caused by Markdown links, fenced prompt examples, metadata URLs, and marketing analytics terms.

3
Files scanned
167
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex

4 июл. 2026 г., 16:05

The static findings are false positives caused by Markdown links, fenced prompt examples, inline-code formatting, and repository metadata URLs. No prompt-injection attempt, hidden command execution, runtime network call, or malicious exfiltration intent was found. One medium semantic issue remains: the optional memory save path uses a <topic> filename placeholder without an explicit sanitization rule.

3
Files scanned
167
Lines analyzed
4
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
Unsanitized Memory Filename Placeholder
The skill tells the agent to write results to memory/ad/conversion-signal-qa/YYYY-MM-DD-<topic>.md after user approval. It does not explicitly require the topic segment to be slugified or stripped of path separators. A malicious or accidental topic value could cause writes outside the intended folder if the host agent uses it literally.
Line 67 contains a user-facing <topic> placeholder inside a write path, and no nearby instruction requires sanitization. The skill also requires user approval before writing, so the issue is a bounded path-handling risk rather than clear malicious intent.
Audited by: codex