Audit History
campaign-architect - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 26, 2026, 10:00 AM | No confirmed findings | 0 | No capability change |
| v7 | Jul 26, 2026, 10:00 AM | No confirmed findings | 0 | No capability change |
| v6 | Jul 13, 2026, 12:24 PM | No confirmed findings | 0 | No capability change |
| v5 | Jul 13, 2026, 12:24 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 12, 2026, 11:07 AM | No confirmed findings | 0 | No capability change |
| v3 | Jul 7, 2026, 06:00 AM | No confirmed findings | 0 | No capability change |
| v2 | Jul 6, 2026, 03:38 PM | No confirmed findings | 0 | No capability change |
| v1 | Jul 4, 2026, 04:01 PM | No confirmed findings | 0 | Baseline |
Jul 26, 2026, 10:00 AM
All 41 static findings are false positives. Markdown delimiters, repository-relative documentation links, public resource URLs, and paid-marketing analysis language were misclassified as command execution, traversal, networking, or system reconnaissance. The skill explicitly treats supplied exports as untrusted input and requires user confirmation before saving results.
Risk Factors
⚙️ External commands (14)
🌐 Network access (4)
Jul 26, 2026, 10:00 AM
All 41 static findings are false positives. Markdown delimiters, repository-relative documentation links, public resource URLs, and paid-marketing analysis language were misclassified as command execution, traversal, networking, or system reconnaissance. The skill explicitly treats supplied exports as untrusted input and requires user confirmation before saving results.
Risk Factors
⚙️ External commands (14)
🌐 Network access (4)
Jul 13, 2026, 12:24 PM
All static findings are false positives caused by Markdown fences, inline code, public hyperlinks, and fixed relative documentation references. The skill contains no executable commands, automatic network requests, path traversal behavior, system reconnaissance, or prompt injection.
Risk Factors
⚙️ External commands (12)
🌐 Network access (4)
Jul 13, 2026, 12:24 PM
All static findings are false positives caused by Markdown fences, inline code, public hyperlinks, and fixed relative documentation references. The skill contains no executable commands, automatic network requests, path traversal behavior, system reconnaissance, or prompt injection.
Risk Factors
⚙️ External commands (12)
🌐 Network access (4)
Jul 12, 2026, 11:07 AM
All 39 static findings are false positives caused by Markdown code fences, inline code, documentation URLs, relative documentation links, and advertising terminology. The skill contains no executable code, unsafe path handling, system reconnaissance, prompt injection, or malicious intent.
Risk Factors
⚙️ External commands (12)
🌐 Network access (4)
Jul 7, 2026, 06:00 AM
All static findings were adjudicated as false positives caused by Markdown fences, inline code spans, hardcoded documentation URLs, and repository-relative links. No executable code, shell invocation, unauthorized network behavior, path traversal intent, prompt injection, or system reconnaissance was found in SKILL.md.
Risk Factors
⚙️ External commands (11)
🌐 Network access (4)
Jul 6, 2026, 03:38 PM
The static findings are false positives from Markdown fences, inline code formatting, repository-relative links, and public documentation URLs. No evidence found of executable commands, hidden network calls, path traversal, prompt injection, or malicious intent in SKILL.md. The skill does handle user ad exports and writes confirmed summaries, so filename sanitization and user authorization should remain explicit.
Risk Factors
⚙️ External commands (11)
🌐 Network access (4)
Jul 4, 2026, 04:01 PM
All static findings were false positives caused by Markdown fences, inline code spans, documentation URLs, repository-relative links, and paid-ad planning language. I found no executable scripts, automatic network calls, uncontrolled filesystem access, prompt injection attempt, or data exfiltration intent in SKILL.md.