Audit History
attribution-reconciler - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 26, 2026, 09:55 AM | 1 confirmed | 0 | No capability change |
| v6 | Jul 26, 2026, 09:55 AM | 1 confirmed | 0 | No capability change |
| v5 | Jul 13, 2026, 12:01 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 13, 2026, 12:01 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 12, 2026, 10:45 AM | No confirmed findings | 0 | No capability change |
| v2 | Jul 6, 2026, 03:12 PM | No confirmed findings | 0 | No capability change |
| v1 | Jul 4, 2026, 03:46 PM | No confirmed findings | 0 | Baseline |
Jul 26, 2026, 09:55 AM
All 35 static findings are false positives caused by Markdown code formatting, relative documentation links, or a public homepage URL; no command execution, network request, path traversal, or system reconnaissance is instructed. The skill handles user-provided marketing exports and can persist order-level reconciliation results after confirmation, so data retention controls should be documented.
Confirmed security concerns (1)
Risk Factors
βοΈ External commands (17)
π Network access (2)
π Filesystem access (15)
Jul 26, 2026, 09:55 AM
All 35 static findings are false positives caused by Markdown code formatting, relative documentation links, or a public homepage URL; no command execution, network request, path traversal, or system reconnaissance is instructed. The skill handles user-provided marketing exports and can persist order-level reconciliation results after confirmation, so data retention controls should be documented.
Confirmed security concerns (1)
Risk Factors
βοΈ External commands (17)
π Network access (2)
π Filesystem access (15)
Jul 13, 2026, 12:01 PM
All 35 static findings are false positives caused by Markdown fences, inline code, relative documentation links, and project homepage metadata. The skill does not execute commands or make network requests, and it requires consent before writing reconciliation results to local memory files. No prompt injection or malicious intent was found.
Risk Factors
βοΈ External commands (17)
π Network access (2)
π Filesystem access (15)
Jul 13, 2026, 12:01 PM
All 35 static findings are false positives caused by Markdown fences, inline code, relative documentation links, and project homepage metadata. The skill does not execute commands or make network requests, and it requires consent before writing reconciliation results to local memory files. No prompt injection or malicious intent was found.
Risk Factors
βοΈ External commands (17)
π Network access (2)
π Filesystem access (15)
Jul 12, 2026, 10:45 AM
All 35 static findings are false positives caused by Markdown fences, inline code, repository-relative links, and GitHub homepage metadata. The skill contains no executable code, command invocation, unsafe path handling, or suspicious network behavior.
Risk Factors
βοΈ External commands (17)
π Network access (2)
π Filesystem access (15)
Jul 6, 2026, 03:12 PM
The static findings are false positives caused by markdown examples, inline code labels, repository reference links, and homepage metadata. No prompt injection, executable command path, network request, or unsafe filesystem traversal was found in SKILL.md.
Risk Factors
βοΈ External commands (16)
π Network access (2)
π Filesystem access (15)
Jul 4, 2026, 03:46 PM
All 33 static findings are false positives from Markdown formatting, inline placeholders, homepage metadata, and repository-relative reference links. No executable code, live network call, command invocation, system reconnaissance, prompt injection, or malicious data flow was found in SKILL.md. The skill also reinforces a safe boundary by treating exported account data as untrusted and asking before writing memory.