πŸ“¦

Audit History

audience-segment-builder - 7 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v7 LatestJul 26, 2026, 09:57 AM No confirmed findings0No capability change
v6 Jul 26, 2026, 09:57 AM No confirmed findings0No capability change
v5 Jul 13, 2026, 12:04 PM No confirmed findings0No capability change
v4 Jul 13, 2026, 12:04 PM No confirmed findings0No capability change
v3 Jul 12, 2026, 10:50 AM 1 confirmed0No capability change
v2 Jul 6, 2026, 03:19 PM No confirmed findings0No capability change
v1 Jul 4, 2026, 03:55 PM No confirmed findings0Baseline

Jul 26, 2026, 09:57 AM

All 31 static detections are false positives. Backticks are Markdown formatting, URLs are metadata links, and relative paths are documentation references or an explicitly confirmed local save location. The skill instructs users to treat exports as untrusted and avoid returning raw PII.

1
Files scanned
81
Lines analyzed
3
Review items
0
False positives ignored
Audited by: claude

Jul 26, 2026, 09:57 AM

All 31 static detections are false positives. Backticks are Markdown formatting, URLs are metadata links, and relative paths are documentation references or an explicitly confirmed local save location. The skill instructs users to treat exports as untrusted and avoid returning raw PII.

1
Files scanned
81
Lines analyzed
3
Review items
0
False positives ignored
Audited by: claude

Jul 13, 2026, 12:04 PM

All 31 static findings are false positives caused by Markdown code fences, inline code, metadata URLs, relative documentation links, and marketing terminology. The skill contains no executable commands, network requests, path traversal behavior, system reconnaissance, prompt injection, or data exfiltration intent.

1
Files scanned
81
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex

Jul 13, 2026, 12:04 PM

All 31 static findings are false positives caused by Markdown code fences, inline code, metadata URLs, relative documentation links, and marketing terminology. The skill contains no executable commands, network requests, path traversal behavior, system reconnaissance, prompt injection, or data exfiltration intent.

1
Files scanned
81
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex

Jul 12, 2026, 10:50 AM

All 31 static alerts are false positives caused by Markdown fences, inline code, URLs, and relative documentation links. A separate privacy ambiguity is present because the skill requests seed rows while also prohibiting raw PII output.

1
Files scanned
81
Lines analyzed
4
Review items
0
False positives ignored

Confirmed security concerns (1)

High
Ambiguous Row-Level Customer Data Output
The skill requests high-value seed rows and says to emit seed rows, while separate instructions prohibit raw PII. This ambiguity can expose customer records in responses or saved artifacts.
Lines 36 and 59 explicitly request seed rows, while lines 54 and 68 prohibit raw PII. The conflicting requirements create a clear privacy risk.
Audited by: codex

Jul 6, 2026, 03:19 PM

Static detections are false positives caused by Markdown code fences, inline code paths, homepage metadata, and relative documentation links. The skill processes user-provided customer and analytics exports, and it tells agents to treat pasted data as untrusted input. No malicious intent, prompt injection, runtime network call, command execution, or path traversal evidence was found.

1
Files scanned
81
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex

Jul 4, 2026, 03:55 PM

All 29 static findings were false positives caused by Markdown code fences, inline-code formatting, static GitHub homepage metadata, and relative documentation links. The skill has privacy-conscious instructions for owned customer exports and explicitly tells agents not to follow instructions embedded in CSVs or echo raw PII. No prompt injection attempt, command execution, network exfiltration, or path traversal intent was found.

1
Files scanned
81
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex