Audit History
budget-pacing-monitor - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 26, 2026, 09:59 AM | No confirmed findings | 1 | No capability change |
| v6 | Jul 26, 2026, 09:59 AM | No confirmed findings | 1 | No capability change |
| v5 | Jul 13, 2026, 12:17 PM | No confirmed findings | 1 | No capability change |
| v4 | Jul 13, 2026, 12:17 PM | No confirmed findings | 1 | No capability change |
| v3 | Jul 12, 2026, 11:04 AM | No confirmed findings | 2 | No capability change |
| v2 | Jul 6, 2026, 03:34 PM | 1 confirmed | 2 | No capability change |
| v1 | Jul 4, 2026, 03:49 PM | No confirmed findings | 1 | Baseline |
Jul 26, 2026, 09:59 AM
Most static alerts are false positives caused by Markdown code formatting, relative documentation links, and descriptive advertising-analysis text. One documented ledger command interpolates a campaign placeholder without quoting or validation, which can permit shell command injection if executed with adversarial input. No prompt-injection language or data-exfiltration intent was found.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (16)
π Network access (2)
π Filesystem access (12)
Jul 26, 2026, 09:59 AM
Most static alerts are false positives caused by Markdown code formatting, relative documentation links, and descriptive advertising-analysis text. One documented ledger command interpolates a campaign placeholder without quoting or validation, which can permit shell command injection if executed with adversarial input. No prompt-injection language or data-exfiltration intent was found.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (16)
π Network access (2)
π Filesystem access (12)
Jul 13, 2026, 12:17 PM
Thirty-four static alerts are false positives caused by Markdown formatting, fixed repository links, benign GitHub metadata, and ordinary campaign terminology. The line 57 alert is confirmed because the skill directs execution of a Python ledger command with an unquoted campaign placeholder. No prompt injection or malicious intent was found.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (16)
π Network access (2)
π Filesystem access (12)
Jul 13, 2026, 12:17 PM
Thirty-four static alerts are false positives caused by Markdown formatting, fixed repository links, benign GitHub metadata, and ordinary campaign terminology. The line 57 alert is confirmed because the skill directs execution of a Python ledger command with an unquoted campaign placeholder. No prompt injection or malicious intent was found.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (16)
π Network access (2)
π Filesystem access (12)
Jul 12, 2026, 11:04 AM
Most detections are false positives caused by Markdown code formatting, documentation links, homepage URLs, and ordinary campaign-monitoring language. Two findings are confirmed: the command template uses an unquoted campaign value, and the save template does not require filename sanitization.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (16)
π Network access (2)
π Filesystem access (12)
Jul 6, 2026, 03:34 PM
Most static findings are Markdown backticks, GitHub homepage metadata, or repository-relative documentation links. I confirmed risk where the skill tells agents to run ledger commands and save files using a user-provided campaign name. No prompt injection attempt was found.
Confirmed security concerns (1)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (16)
π Network access (2)
π Filesystem access (12)
Jul 4, 2026, 03:49 PM
Most static findings are Markdown code spans, code fences, homepage metadata, or repository-relative documentation links. I confirmed one medium external-command risk because the skill tells the agent to run a local ledger command with a user-supplied campaign placeholder. No evidence found of prompt injection, credential exfiltration, or malicious network behavior.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.