πŸ“¦

Audit History

attribution-reconciler - 7 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v7 LatestJul 26, 2026, 09:55 AM 1 confirmed0No capability change
v6 Jul 26, 2026, 09:55 AM 1 confirmed0No capability change
v5 Jul 13, 2026, 12:01 PM No confirmed findings0No capability change
v4 Jul 13, 2026, 12:01 PM No confirmed findings0No capability change
v3 Jul 12, 2026, 10:45 AM No confirmed findings0No capability change
v2 Jul 6, 2026, 03:12 PM No confirmed findings0No capability change
v1 Jul 4, 2026, 03:46 PM No confirmed findings0Baseline

Jul 26, 2026, 09:55 AM

All 35 static findings are false positives caused by Markdown code formatting, relative documentation links, or a public homepage URL; no command execution, network request, path traversal, or system reconnaissance is instructed. The skill handles user-provided marketing exports and can persist order-level reconciliation results after confirmation, so data retention controls should be documented.

1
Files scanned
98
Lines analyzed
4
Review items
0
False positives ignored

Confirmed security concerns (1)

Low
Sensitive Order Data Persistence
The skill may save reconciliation workbooks containing order IDs, timestamps, and monetary values to persistent memory after confirmation. It does not specify retention, minimization, or redaction controls.
The skill explicitly describes order-level fields and persistent memory destinations. The save action requires confirmation, which reduces but does not remove data-retention risk.
Audited by: claude

Jul 26, 2026, 09:55 AM

All 35 static findings are false positives caused by Markdown code formatting, relative documentation links, or a public homepage URL; no command execution, network request, path traversal, or system reconnaissance is instructed. The skill handles user-provided marketing exports and can persist order-level reconciliation results after confirmation, so data retention controls should be documented.

1
Files scanned
98
Lines analyzed
4
Review items
0
False positives ignored

Confirmed security concerns (1)

Low
Sensitive Order Data Persistence
The skill may save reconciliation workbooks containing order IDs, timestamps, and monetary values to persistent memory after confirmation. It does not specify retention, minimization, or redaction controls.
The skill explicitly describes order-level fields and persistent memory destinations. The save action requires confirmation, which reduces but does not remove data-retention risk.
Audited by: claude

Jul 13, 2026, 12:01 PM

All 35 static findings are false positives caused by Markdown fences, inline code, relative documentation links, and project homepage metadata. The skill does not execute commands or make network requests, and it requires consent before writing reconciliation results to local memory files. No prompt injection or malicious intent was found.

1
Files scanned
98
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex

Jul 13, 2026, 12:01 PM

All 35 static findings are false positives caused by Markdown fences, inline code, relative documentation links, and project homepage metadata. The skill does not execute commands or make network requests, and it requires consent before writing reconciliation results to local memory files. No prompt injection or malicious intent was found.

1
Files scanned
98
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex

Jul 12, 2026, 10:45 AM

All 35 static findings are false positives caused by Markdown fences, inline code, repository-relative links, and GitHub homepage metadata. The skill contains no executable code, command invocation, unsafe path handling, or suspicious network behavior.

1
Files scanned
98
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex

Jul 6, 2026, 03:12 PM

The static findings are false positives caused by markdown examples, inline code labels, repository reference links, and homepage metadata. No prompt injection, executable command path, network request, or unsafe filesystem traversal was found in SKILL.md.

1
Files scanned
98
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex

Jul 4, 2026, 03:46 PM

All 33 static findings are false positives from Markdown formatting, inline placeholders, homepage metadata, and repository-relative reference links. No executable code, live network call, command invocation, system reconnaissance, prompt injection, or malicious data flow was found in SKILL.md. The skill also reinforces a safe boundary by treating exported account data as untrusted and asking before writing memory.

1
Files scanned
98
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex