Audit History
audience-segment-builder - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 26, 2026, 09:57 AM | No confirmed findings | 0 | No capability change |
| v6 | Jul 26, 2026, 09:57 AM | No confirmed findings | 0 | No capability change |
| v5 | Jul 13, 2026, 12:04 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 13, 2026, 12:04 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 12, 2026, 10:50 AM | 1 confirmed | 0 | No capability change |
| v2 | Jul 6, 2026, 03:19 PM | No confirmed findings | 0 | No capability change |
| v1 | Jul 4, 2026, 03:55 PM | No confirmed findings | 0 | Baseline |
Jul 26, 2026, 09:57 AM
All 31 static detections are false positives. Backticks are Markdown formatting, URLs are metadata links, and relative paths are documentation references or an explicitly confirmed local save location. The skill instructs users to treat exports as untrusted and avoid returning raw PII.
Risk Factors
βοΈ External commands (14)
π Network access (2)
π Filesystem access (13)
Jul 26, 2026, 09:57 AM
All 31 static detections are false positives. Backticks are Markdown formatting, URLs are metadata links, and relative paths are documentation references or an explicitly confirmed local save location. The skill instructs users to treat exports as untrusted and avoid returning raw PII.
Risk Factors
βοΈ External commands (14)
π Network access (2)
π Filesystem access (13)
Jul 13, 2026, 12:04 PM
All 31 static findings are false positives caused by Markdown code fences, inline code, metadata URLs, relative documentation links, and marketing terminology. The skill contains no executable commands, network requests, path traversal behavior, system reconnaissance, prompt injection, or data exfiltration intent.
Risk Factors
βοΈ External commands (14)
π Network access (2)
π Filesystem access (13)
Jul 13, 2026, 12:04 PM
All 31 static findings are false positives caused by Markdown code fences, inline code, metadata URLs, relative documentation links, and marketing terminology. The skill contains no executable commands, network requests, path traversal behavior, system reconnaissance, prompt injection, or data exfiltration intent.
Risk Factors
βοΈ External commands (14)
π Network access (2)
π Filesystem access (13)
Jul 12, 2026, 10:50 AM
All 31 static alerts are false positives caused by Markdown fences, inline code, URLs, and relative documentation links. A separate privacy ambiguity is present because the skill requests seed rows while also prohibiting raw PII output.
Confirmed security concerns (1)
Risk Factors
βοΈ External commands (14)
π Network access (2)
π Filesystem access (13)
Jul 6, 2026, 03:19 PM
Static detections are false positives caused by Markdown code fences, inline code paths, homepage metadata, and relative documentation links. The skill processes user-provided customer and analytics exports, and it tells agents to treat pasted data as untrusted input. No malicious intent, prompt injection, runtime network call, command execution, or path traversal evidence was found.
Risk Factors
βοΈ External commands (12)
π Network access (2)
π Filesystem access (13)
Jul 4, 2026, 03:55 PM
All 29 static findings were false positives caused by Markdown code fences, inline-code formatting, static GitHub homepage metadata, and relative documentation links. The skill has privacy-conscious instructions for owned customer exports and explicitly tells agents not to follow instructions embedded in CSVs or echo raw PII. No prompt injection attempt, command execution, network exfiltration, or path traversal intent was found.