Audit History
bid-strategy-planner - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 26, 2026, 09:58 AM | 1 confirmed | 0 | No capability change |
| v6 | Jul 26, 2026, 09:58 AM | 1 confirmed | 0 | No capability change |
| v5 | Jul 13, 2026, 12:08 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 13, 2026, 12:08 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 12, 2026, 10:53 AM | No confirmed findings | 0 | No capability change |
| v2 | Jul 6, 2026, 03:23 PM | No confirmed findings | 0 | No capability change |
| v1 | Jul 4, 2026, 03:59 PM | No confirmed findings | 0 | Baseline |
Jul 26, 2026, 09:58 AM
The 57 static alerts are false positives from Markdown links, backticks, headings, and homepage metadata; the skill contains no executed shell commands, network requests, or system reconnaissance. A medium-risk design issue remains: the documented save filename includes an unsanitized campaign placeholder. The content also explicitly treats imported data as untrusted input.
Confirmed security concerns (1)
Risk Factors
π Filesystem access (17)
βοΈ External commands (17)
π Network access (2)
Jul 26, 2026, 09:58 AM
The 57 static alerts are false positives from Markdown links, backticks, headings, and homepage metadata; the skill contains no executed shell commands, network requests, or system reconnaissance. A medium-risk design issue remains: the documented save filename includes an unsanitized campaign placeholder. The content also explicitly treats imported data as untrusted input.
Confirmed security concerns (1)
Risk Factors
π Filesystem access (17)
βοΈ External commands (17)
π Network access (2)
Jul 13, 2026, 12:08 PM
All 57 static findings are false positives caused by Markdown links, backtick formatting, repository metadata, and ordinary advertising terminology. The skill contains no executable code, network requests, system reconnaissance, traversal operations, or prompt-injection instructions.
Risk Factors
π Filesystem access (17)
βοΈ External commands (17)
π Network access (2)
Jul 13, 2026, 12:08 PM
All 57 static findings are false positives caused by Markdown links, backtick formatting, repository metadata, and ordinary advertising terminology. The skill contains no executable code, network requests, system reconnaissance, traversal operations, or prompt-injection instructions.
Risk Factors
π Filesystem access (17)
βοΈ External commands (17)
π Network access (2)
Jul 12, 2026, 10:53 AM
All 57 static findings are false positives caused by Markdown links, formatting, metadata, and advertising terminology. The reviewed files contain no executable commands, active network requests, path traversal behavior, reconnaissance, or prompt injection.
Risk Factors
π Filesystem access (17)
βοΈ External commands (17)
π Network access (2)
Jul 6, 2026, 03:23 PM
The static alerts were reviewed in context. The path traversal, external command, network, and blocker findings are false positives caused by Markdown links, inline code examples, metadata URLs, and planning workflow language. No prompt injection, exfiltration intent, or executable behavior was found in the analyzed files.
Risk Factors
π Filesystem access (17)
βοΈ External commands (16)
π Network access (2)
Jul 4, 2026, 03:59 PM
All static findings are false positives caused by Markdown links, fenced examples, inline placeholders, and repository homepage metadata. I found no evidence of command execution, data exfiltration, path traversal, prompt injection, or host reconnaissance in SKILL.md or references/bid-strategy-matrix.md.