Skills campaign-planner Audit History
πŸ“¦

Audit History

campaign-planner - 6 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v6 LatestJul 23, 2026, 04:41 AM 1 confirmed0No capability change
v5 Jul 12, 2026, 11:10 AM 1 confirmed0No capability change
v4 Jul 12, 2026, 11:10 AM 1 confirmed0No capability change
v3 Jul 12, 2026, 11:10 AM 1 confirmed0No capability change
v2 Jul 6, 2026, 03:43 PM No confirmed findings0No capability change
v1 Jul 4, 2026, 04:00 PM No confirmed findings0Baseline

Jul 23, 2026, 04:41 AM

All 35 static findings are false positives caused by Markdown links, code fences, inline labels, ordinary marketing terms, and GitHub metadata. The skill does direct the agent to persist campaign details in memory files and a shared hot cache, creating a separate confidentiality risk for sensitive launch plans.

3
Files scanned
604
Lines analyzed
4
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
Persistent Storage of Sensitive Campaign Details
The skill saves campaign plans and promotes budgets, launch dates, objectives, and KPI targets to persistent memory. Confidential strategy may remain available beyond the request without explicit user approval.
The skill contract explicitly requires a saved plan and promotion of durable campaign facts to a hot cache. The security impact depends on host isolation and the sensitivity of user inputs.
Audited by: codex

Jul 12, 2026, 11:10 AM

All 35 static alerts are false positives caused by Markdown links, code fences, inline formatting, metadata URLs, or marketing terminology. No executable commands, network requests, path traversal operations, or prompt injection were found. The skill does direct agents to persist plans and update a shared memory file.

3
Files scanned
604
Lines analyzed
4
Review items
0
False positives ignored

Confirmed security concerns (1)

Low
Persistent Workspace Writes
The skill directs agents to save campaign plans and update a shared hot-cache file without an explicit confirmation step.
The skill contract and final workflow step explicitly require both writes, making the persistence behavior clear and directly evidenced.
Audited by: codex

Jul 12, 2026, 11:10 AM

All 35 static alerts are false positives caused by Markdown links, code fences, inline formatting, metadata URLs, or marketing terminology. No executable commands, network requests, path traversal operations, or prompt injection were found. The skill does direct agents to persist plans and update a shared memory file.

3
Files scanned
604
Lines analyzed
4
Review items
0
False positives ignored

Confirmed security concerns (1)

Low
Persistent Workspace Writes
The skill directs agents to save campaign plans and update a shared hot-cache file without an explicit confirmation step.
The skill contract and final workflow step explicitly require both writes, making the persistence behavior clear and directly evidenced.
Audited by: codex

Jul 12, 2026, 11:10 AM

All 35 static alerts are false positives caused by Markdown links, code fences, inline formatting, metadata URLs, or marketing terminology. No executable commands, network requests, path traversal operations, or prompt injection were found. The skill does direct agents to persist plans and update a shared memory file.

3
Files scanned
604
Lines analyzed
4
Review items
0
False positives ignored

Confirmed security concerns (1)

Low
Persistent Workspace Writes
The skill directs agents to save campaign plans and update a shared hot-cache file without an explicit confirmation step.
The skill contract and final workflow step explicitly require both writes, making the persistence behavior clear and directly evidenced.
Audited by: codex

Jul 6, 2026, 03:43 PM

All static findings are false positives caused by Markdown fences, relative documentation links, metadata URLs, and marketing table terms. No command execution, filesystem traversal, network calls, prompt injection, or malicious intent were found in the reviewed files.

3
Files scanned
604
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex

Jul 4, 2026, 04:00 PM

All 34 static findings were adjudicated as false positives. The flagged patterns are Markdown links, fenced-code delimiters, inline code labels, homepage metadata, and marketing budget language, not executable commands, malicious network calls, or unsafe path handling. No prompt injection, data exfiltration, or business-logic abuse was found in the reviewed files.

3
Files scanned
602
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex