Audit History
ad-creative-builder - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 26, 2026, 09:52 AM | No confirmed findings | 0 | No capability change |
| v6 | Jul 26, 2026, 09:52 AM | No confirmed findings | 0 | No capability change |
| v5 | Jul 13, 2026, 11:48 AM | 1 confirmed | 3 | No capability change |
| v4 | Jul 13, 2026, 11:48 AM | 1 confirmed | 3 | No capability change |
| v3 | Jul 12, 2026, 10:37 AM | 1 confirmed | 1 | No capability change |
| v2 | Jul 6, 2026, 03:03 PM | No confirmed findings | 0 | No capability change |
| v1 | Jul 4, 2026, 03:49 PM | No confirmed findings | 0 | Baseline |
Jul 26, 2026, 09:52 AM
All 30 static findings are false positives. The detected shell-execution markers are Markdown code fences or inline-code delimiters, URLs are documentation links, and traversal sequences are relative Markdown references. The skill explicitly treats imported content as untrusted and requires user confirmation before saving results.
Risk Factors
βοΈ External commands (15)
π Network access (3)
π Filesystem access (12)
Jul 26, 2026, 09:52 AM
All 30 static findings are false positives. The detected shell-execution markers are Markdown code fences or inline-code delimiters, URLs are documentation links, and traversal sequences are relative Markdown references. The skill explicitly treats imported content as untrusted and requires user confirmation before saving results.
Risk Factors
βοΈ External commands (15)
π Network access (3)
π Filesystem access (12)
Jul 13, 2026, 11:48 AM
Most command and traversal alerts are Markdown formatting or fixed repository links with no dynamic execution. Two external-command findings are confirmed because the workflow directs agents to an unaudited script. The user-derived save path and unrestricted destination retrieval also create high-risk path and network exposure.
Confirmed security concerns (1)
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (15)
π Network access (3)
π Filesystem access (12)
Jul 13, 2026, 11:48 AM
Most command and traversal alerts are Markdown formatting or fixed repository links with no dynamic execution. Two external-command findings are confirmed because the workflow directs agents to an unaudited script. The user-derived save path and unrestricted destination retrieval also create high-risk path and network exposure.
Confirmed security concerns (1)
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (15)
π Network access (3)
π Filesystem access (12)
Jul 12, 2026, 10:37 AM
Twenty-nine static findings are Markdown formatting, metadata URLs, or documentation links without command execution or unsafe path access. One high-severity finding is confirmed because the save instruction places a user-controlled offer value into a filename without requiring sanitization. Semantic review also found that the workflow fetches a user-supplied destination URL without requiring protections against internal network access.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (15)
π Network access (3)
π Filesystem access (12)
Jul 6, 2026, 03:03 PM
All static findings are false positives from Markdown formatting, inline path examples, metadata URLs, and relative documentation links. I found no evidence of executable code, secret exfiltration, or prompt injection in SKILL.md.
Risk Factors
βοΈ External commands (14)
π Network access (3)
π Filesystem access (14)
Jul 4, 2026, 03:49 PM
All static findings appear to be false positives caused by Markdown code fences, inline backticks, documentation URLs, and relative links. No prompt injection, data exfiltration, executable command path, or unsafe path handling was found in SKILL.md context.