Audit History
cold-outbound-sequencer - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 26, 2026, 10:01 AM | No confirmed findings | 0 | No capability change |
| v6 | Jul 26, 2026, 10:01 AM | No confirmed findings | 0 | No capability change |
| v5 | Jul 13, 2026, 12:27 PM | 1 confirmed | 0 | No capability change |
| v4 | Jul 13, 2026, 12:27 PM | 1 confirmed | 0 | No capability change |
| v3 | Jul 12, 2026, 11:13 AM | 1 confirmed | 0 | No capability change |
| v2 | Jul 6, 2026, 03:46 PM | 1 confirmed | 0 | No capability change |
| v1 | Jul 4, 2026, 03:53 PM | No confirmed findings | 0 | Baseline |
Jul 26, 2026, 10:01 AM
All 37 static matches are false positives caused by Markdown code delimiters, documentation URLs, and relative repository links. The skill does not execute commands, make network requests, read environment variables, or resolve untrusted filesystem paths. Its instructions explicitly treat exports as untrusted and require confirmation before saving results.
Risk Factors
βοΈ External commands (14)
π Network access (2)
π Filesystem access (20)
π Env variables (1)
Jul 26, 2026, 10:01 AM
All 37 static matches are false positives caused by Markdown code delimiters, documentation URLs, and relative repository links. The skill does not execute commands, make network requests, read environment variables, or resolve untrusted filesystem paths. Its instructions explicitly treat exports as untrusted and require confirmation before saving results.
Risk Factors
βοΈ External commands (14)
π Network access (2)
π Filesystem access (20)
π Env variables (1)
Jul 13, 2026, 12:27 PM
All 35 static detections are false positives caused by Markdown fences, inline code, fixed URLs, and relative documentation links. The skill contains no executable commands, network requests, environment access, or path traversal logic. A medium concern remains because its sequencing and mailbox-distribution guidance can support unsolicited bulk outreach despite embedded compliance controls.
Confirmed security concerns (1)
Risk Factors
βοΈ External commands (12)
π Network access (2)
π Filesystem access (20)
π Env variables (1)
Jul 13, 2026, 12:27 PM
All 35 static detections are false positives caused by Markdown fences, inline code, fixed URLs, and relative documentation links. The skill contains no executable commands, network requests, environment access, or path traversal logic. A medium concern remains because its sequencing and mailbox-distribution guidance can support unsolicited bulk outreach despite embedded compliance controls.
Confirmed security concerns (1)
Risk Factors
βοΈ External commands (12)
π Network access (2)
π Filesystem access (20)
π Env variables (1)
Jul 12, 2026, 11:13 AM
All 35 static findings are false positives caused by Markdown fences, inline code, repository metadata, and fixed relative documentation links. A separate medium-risk concern remains because the workflow can scale unsolicited outreach and improve filter avoidance, although it includes consent, suppression, and legal guardrails.
Confirmed security concerns (1)
Risk Factors
βοΈ External commands (12)
π Network access (2)
π Filesystem access (20)
π Env variables (1)
Jul 6, 2026, 03:46 PM
Static findings were reviewed against SKILL.md. The Ruby backtick, hardcoded URL, path traversal, and environment access detections are false positives from markdown fences, metadata URLs, repository links, and prose paths. The substantive concern is misuse potential because the skill helps design cold outbound email programs.
Confirmed security concerns (1)
Risk Factors
βοΈ External commands (11)
π Network access (2)
π Filesystem access (20)
π Env variables (1)
Jul 4, 2026, 03:53 PM
All 34 static findings were adjudicated as false positives. The flagged backticks are Markdown fences or inline paths, URLs are repository metadata, and relative paths are documentation links or user-confirmed memory save locations. No prompt injection, code execution, credential access, or malicious network behavior was found in SKILL.md.