Audit History
campaign-planner - 6 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v6 Latest | Jul 23, 2026, 04:41 AM | 1 confirmed | 0 | No capability change |
| v5 | Jul 12, 2026, 11:10 AM | 1 confirmed | 0 | No capability change |
| v4 | Jul 12, 2026, 11:10 AM | 1 confirmed | 0 | No capability change |
| v3 | Jul 12, 2026, 11:10 AM | 1 confirmed | 0 | No capability change |
| v2 | Jul 6, 2026, 03:43 PM | No confirmed findings | 0 | No capability change |
| v1 | Jul 4, 2026, 04:00 PM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 04:41 AM
All 35 static findings are false positives caused by Markdown links, code fences, inline labels, ordinary marketing terms, and GitHub metadata. The skill does direct the agent to persist campaign details in memory files and a shared hot cache, creating a separate confidentiality risk for sensitive launch plans.
Confirmed security concerns (1)
Risk Factors
βοΈ External commands (14)
π Filesystem access (16)
π Network access (2)
Jul 12, 2026, 11:10 AM
All 35 static alerts are false positives caused by Markdown links, code fences, inline formatting, metadata URLs, or marketing terminology. No executable commands, network requests, path traversal operations, or prompt injection were found. The skill does direct agents to persist plans and update a shared memory file.
Confirmed security concerns (1)
Risk Factors
βοΈ External commands (14)
π Filesystem access (16)
π Network access (2)
Jul 12, 2026, 11:10 AM
All 35 static alerts are false positives caused by Markdown links, code fences, inline formatting, metadata URLs, or marketing terminology. No executable commands, network requests, path traversal operations, or prompt injection were found. The skill does direct agents to persist plans and update a shared memory file.
Confirmed security concerns (1)
Risk Factors
βοΈ External commands (14)
π Filesystem access (16)
π Network access (2)
Jul 12, 2026, 11:10 AM
All 35 static alerts are false positives caused by Markdown links, code fences, inline formatting, metadata URLs, or marketing terminology. No executable commands, network requests, path traversal operations, or prompt injection were found. The skill does direct agents to persist plans and update a shared memory file.
Confirmed security concerns (1)
Risk Factors
βοΈ External commands (14)
π Filesystem access (16)
π Network access (2)
Jul 6, 2026, 03:43 PM
All static findings are false positives caused by Markdown fences, relative documentation links, metadata URLs, and marketing table terms. No command execution, filesystem traversal, network calls, prompt injection, or malicious intent were found in the reviewed files.
Risk Factors
βοΈ External commands (14)
π Filesystem access (16)
π Network access (2)
Jul 4, 2026, 04:00 PM
All 34 static findings were adjudicated as false positives. The flagged patterns are Markdown links, fenced-code delimiters, inline code labels, homepage metadata, and marketing budget language, not executable commands, malicious network calls, or unsafe path handling. No prompt injection, data exfiltration, or business-logic abuse was found in the reviewed files.