πŸ“¦

Audit History

cold-outbound-sequencer - 7 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v7 LatestJul 26, 2026, 10:01 AM No confirmed findings0No capability change
v6 Jul 26, 2026, 10:01 AM No confirmed findings0No capability change
v5 Jul 13, 2026, 12:27 PM 1 confirmed0No capability change
v4 Jul 13, 2026, 12:27 PM 1 confirmed0No capability change
v3 Jul 12, 2026, 11:13 AM 1 confirmed0No capability change
v2 Jul 6, 2026, 03:46 PM 1 confirmed0No capability change
v1 Jul 4, 2026, 03:53 PM No confirmed findings0Baseline

Jul 26, 2026, 10:01 AM

All 37 static matches are false positives caused by Markdown code delimiters, documentation URLs, and relative repository links. The skill does not execute commands, make network requests, read environment variables, or resolve untrusted filesystem paths. Its instructions explicitly treat exports as untrusted and require confirmation before saving results.

1
Files scanned
93
Lines analyzed
4
Review items
0
False positives ignored
Audited by: claude

Jul 26, 2026, 10:01 AM

All 37 static matches are false positives caused by Markdown code delimiters, documentation URLs, and relative repository links. The skill does not execute commands, make network requests, read environment variables, or resolve untrusted filesystem paths. Its instructions explicitly treat exports as untrusted and require confirmation before saving results.

1
Files scanned
93
Lines analyzed
4
Review items
0
False positives ignored
Audited by: claude

Jul 13, 2026, 12:27 PM

All 35 static detections are false positives caused by Markdown fences, inline code, fixed URLs, and relative documentation links. The skill contains no executable commands, network requests, environment access, or path traversal logic. A medium concern remains because its sequencing and mailbox-distribution guidance can support unsolicited bulk outreach despite embedded compliance controls.

1
Files scanned
93
Lines analyzed
5
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
Cold Outreach Abuse Potential
The skill plans repeated cold-list touches, mailbox warmup, and distributed sending volume. These controls can also support unsolicited outreach or provider-limit evasion.
Lines 57-61 explicitly plan cold-list cadence, mailbox distribution, and volume ramping. Compliance exits reduce misuse risk but do not remove it.
Audited by: codex

Jul 13, 2026, 12:27 PM

All 35 static detections are false positives caused by Markdown fences, inline code, fixed URLs, and relative documentation links. The skill contains no executable commands, network requests, environment access, or path traversal logic. A medium concern remains because its sequencing and mailbox-distribution guidance can support unsolicited bulk outreach despite embedded compliance controls.

1
Files scanned
93
Lines analyzed
5
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
Cold Outreach Abuse Potential
The skill plans repeated cold-list touches, mailbox warmup, and distributed sending volume. These controls can also support unsolicited outreach or provider-limit evasion.
Lines 57-61 explicitly plan cold-list cadence, mailbox distribution, and volume ramping. Compliance exits reduce misuse risk but do not remove it.
Audited by: codex

Jul 12, 2026, 11:13 AM

All 35 static findings are false positives caused by Markdown fences, inline code, repository metadata, and fixed relative documentation links. A separate medium-risk concern remains because the workflow can scale unsolicited outreach and improve filter avoidance, although it includes consent, suppression, and legal guardrails.

1
Files scanned
93
Lines analyzed
5
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
Cold-Outreach Scaling Can Facilitate Spam
The skill plans cold-email sequences, mailbox warmup, send throttles, and volume distribution. These capabilities can scale unsolicited messaging or reduce filtering effectiveness despite included compliance safeguards.
The stated purpose and workflow clearly optimize cold-outreach volume and deliverability. Abuse intent is not explicit because the skill also requires opt-outs and lawful-basis checks.
Audited by: codex

Jul 6, 2026, 03:46 PM

Static findings were reviewed against SKILL.md. The Ruby backtick, hardcoded URL, path traversal, and environment access detections are false positives from markdown fences, metadata URLs, repository links, and prose paths. The substantive concern is misuse potential because the skill helps design cold outbound email programs.

1
Files scanned
93
Lines analyzed
5
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
Cold Outreach Abuse Potential
The skill intentionally designs B2B cold outbound sequences, reply triage, warmup, and send throttles. These features can support unsolicited or high-volume outreach if used without consent and suppression controls.
Lines 18 and 57-61 directly describe cold outbound sequence design, exit rules, send throttles, and compliance guardrails. The skill includes safeguards, so the finding is misuse potential rather than direct malicious code.
Audited by: codex

Jul 4, 2026, 03:53 PM

All 34 static findings were adjudicated as false positives. The flagged backticks are Markdown fences or inline paths, URLs are repository metadata, and relative paths are documentation links or user-confirmed memory save locations. No prompt injection, code execution, credential access, or malicious network behavior was found in SKILL.md.

1
Files scanned
93
Lines analyzed
4
Review items
0
False positives ignored
Audited by: codex