Audit History
ad-test-designer - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 26, 2026, 09:54 AM | No confirmed findings | 0 | No capability change |
| v8 | Jul 26, 2026, 09:54 AM | No confirmed findings | 0 | No capability change |
| v7 | Jul 13, 2026, 11:58 AM | No confirmed findings | 0 | No capability change |
| v6 | Jul 13, 2026, 11:58 AM | No confirmed findings | 0 | No capability change |
| v5 | Jul 12, 2026, 10:42 AM | 1 confirmed | 1 | No capability change |
| v4 | Jul 6, 2026, 03:07 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 9, 2026, 12:06 PM | No confirmed findings | 3 | No capability change |
| v2 | Jul 6, 2026, 03:07 PM | No confirmed findings | 0 | No capability change |
| v1 | Jul 4, 2026, 03:52 PM | 1 confirmed | 0 | Baseline |
Jul 26, 2026, 09:54 AM
All 35 static alerts are false positives caused by Markdown backticks, relative documentation links, metadata, or the decimal alpha notation. The sole documented command runs a fixed local statistical helper and contains no evidence of network access, arbitrary code execution, data exfiltration, or prompt injection. The skill also explicitly treats exported CSV content as untrusted data and requires consent before saving results.
Risk Factors
📁 Filesystem access (12)
⚙️ External commands (20)
🌐 Network access (2)
Jul 26, 2026, 09:54 AM
All 35 static alerts are false positives caused by Markdown backticks, relative documentation links, metadata, or the decimal alpha notation. The sole documented command runs a fixed local statistical helper and contains no evidence of network access, arbitrary code execution, data exfiltration, or prompt injection. The skill also explicitly treats exported CSV content as untrusted data and requires consent before saving results.
Risk Factors
📁 Filesystem access (12)
⚙️ External commands (20)
🌐 Network access (2)
Jul 13, 2026, 11:58 AM
All 35 static alerts are false positives caused by Markdown syntax, fixed repository links, decimal notation, and homepage metadata. The command example invokes a fixed local statistical helper with numeric inputs; no injection, arbitrary traversal, credential use, or exfiltration intent appears.
Risk Factors
📁 Filesystem access (12)
⚙️ External commands (20)
🌐 Network access (2)
Jul 13, 2026, 11:58 AM
All 35 static alerts are false positives caused by Markdown syntax, fixed repository links, decimal notation, and homepage metadata. The command example invokes a fixed local statistical helper with numeric inputs; no injection, arbitrary traversal, credential use, or exfiltration intent appears.
Risk Factors
📁 Filesystem access (12)
⚙️ External commands (20)
🌐 Network access (2)
Jul 12, 2026, 10:42 AM
Most static alerts are false positives caused by Markdown code formatting and relative links to repository documentation. The skill also recommends an unaudited Python helper and can persist test summaries after consent, so those behaviors remain disclosed.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
📁 Filesystem access (12)
⚙️ External commands (20)
🌐 Network access (2)
Jul 6, 2026, 03:07 PM
The command and network findings are false positives caused by Markdown formatting and repository metadata. The path traversal findings are fixed documentation links, and I found no command execution, data exfiltration, arbitrary file access, or prompt injection intent.
Risk Factors
📁 Filesystem access (10)
⚙️ External commands (13)
🌐 Network access (2)
Jul 9, 2026, 12:06 PM
Most static alerts are false positives from markdown code fences, relative repository links, and homepage metadata. I confirmed three medium-risk command-invocation instructions for a local experiment.py helper; no prompt injection, data exfiltration intent, or malicious network behavior was found.
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
📁 Filesystem access (10)
⚙️ External commands (16)
🌐 Network access (2)
Jul 6, 2026, 03:07 PM
The command and network findings are false positives caused by Markdown formatting and repository metadata. The path traversal findings are fixed documentation links, and I found no command execution, data exfiltration, arbitrary file access, or prompt injection intent.
Risk Factors
📁 Filesystem access (10)
⚙️ External commands (13)
🌐 Network access (2)
Jul 4, 2026, 03:52 PM
Static alerts are false positives from Markdown links, fenced examples, inline placeholders, and repository metadata; I found no shell execution or network call. One semantic issue remains: the optional memory filename includes a topic value without sanitization guidance, which could create unsafe paths in permissive hosts.