Audit History
brief-generator - 4 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v4 Latest | Jul 12, 2026, 10:57 AM | No confirmed findings | 0 | No capability change |
| v3 | Jul 12, 2026, 10:57 AM | No confirmed findings | 0 | No capability change |
| v2 | Jul 6, 2026, 03:26 PM | No confirmed findings | 0 | No capability change |
| v1 | Jul 4, 2026, 03:54 PM | No confirmed findings | 0 | Baseline |
Jul 12, 2026, 10:57 AM
All 37 static findings are false positives caused by Markdown formatting, fixed repository links, template wording, or public metadata URLs. No executable commands, dynamic paths, prompt injection, unauthorized network activity, or malicious intent were found.
Risk Factors
π Filesystem access (16)
βοΈ External commands (11)
π Network access (2)
Jul 12, 2026, 10:57 AM
All 37 static findings are false positives caused by Markdown formatting, fixed repository links, template wording, or public metadata URLs. No executable commands, dynamic paths, prompt injection, unauthorized network activity, or malicious intent were found.
Risk Factors
π Filesystem access (16)
βοΈ External commands (11)
π Network access (2)
Jul 6, 2026, 03:26 PM
The static findings are false positives from markdown links, fenced examples, inline-code path names, and GitHub metadata. I found no evidence of prompt injection, command execution, credential access, network calls, or malicious data exfiltration. The skill writes generated briefs to local memory as part of its stated workflow.
Risk Factors
π Filesystem access (18)
βοΈ External commands (14)
π Network access (2)
Jul 4, 2026, 03:54 PM
Static findings were reviewed against SKILL.md and the referenced brief templates. No executable commands, live network calls, path traversal behavior, prompt injection, or system reconnaissance instructions were found. The flagged items are Markdown links, fenced examples, inline file paths, homepage metadata, and ordinary influencer-brief compliance language.