Skills contract-helper Audit History
πŸ“¦

Audit History

contract-helper - 8 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v8 LatestJul 26, 2026, 10:05 AM No confirmed findings0No capability change
v7 Jul 26, 2026, 10:05 AM No confirmed findings0No capability change
v6 Jul 13, 2026, 12:40 PM 1 confirmed0No capability change
v5 Jul 13, 2026, 12:40 PM 1 confirmed0No capability change
v4 Jul 12, 2026, 11:43 AM 1 confirmed0No capability change
v3 Jul 7, 2026, 06:08 AM No confirmed findings0No capability change
v2 Jul 6, 2026, 04:21 PM No confirmed findings0No capability change
v1 Jul 4, 2026, 03:53 PM No confirmed findings0Baseline

Jul 26, 2026, 10:05 AM

All 36 static findings are false positives caused by Markdown syntax, documentation links, and contract-template language. The skill provides legal drafting guidance and documents optional integrations, but contains no executable commands, network requests, or prompt-injection content. Contract data should still be handled under the user’s applicable privacy and retention policies.

2
Files scanned
606
Lines analyzed
3
Review items
0
False positives ignored
Audited by: claude

Jul 26, 2026, 10:05 AM

All 36 static findings are false positives caused by Markdown syntax, documentation links, and contract-template language. The skill provides legal drafting guidance and documents optional integrations, but contains no executable commands, network requests, or prompt-injection content. Contract data should still be handled under the user’s applicable privacy and retention policies.

2
Files scanned
606
Lines analyzed
3
Review items
0
False positives ignored
Audited by: claude

Jul 13, 2026, 12:40 PM

All 36 static findings are false positives caused by Markdown syntax, fixed repository links, marketing terms, and metadata URLs. No reviewed content executes commands, resolves user-controlled traversal paths, performs reconnaissance, or sends network requests. One semantic concern remains: the skill stores sensitive signed terms in durable memory without explicit confirmation.

2
Files scanned
606
Lines analyzed
4
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
Sensitive Contract Terms Persisted Without Confirmation
The skill stores final rates, rights, exclusivity, and payment details in durable memory and an event log without explicit user confirmation.
Lines 34-35 and 67 explicitly require these writes, so the persistence behavior is clear. No external exfiltration is present.
Audited by: codex

Jul 13, 2026, 12:40 PM

All 36 static findings are false positives caused by Markdown syntax, fixed repository links, marketing terms, and metadata URLs. No reviewed content executes commands, resolves user-controlled traversal paths, performs reconnaissance, or sends network requests. One semantic concern remains: the skill stores sensitive signed terms in durable memory without explicit confirmation.

2
Files scanned
606
Lines analyzed
4
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
Sensitive Contract Terms Persisted Without Confirmation
The skill stores final rates, rights, exclusivity, and payment details in durable memory and an event log without explicit user confirmation.
Lines 34-35 and 67 explicitly require these writes, so the persistence behavior is clear. No external exfiltration is present.
Audited by: codex

Jul 12, 2026, 11:43 AM

All 36 static findings are false positives caused by Markdown syntax, relative documentation links, metadata URLs, and ordinary marketing language. No executable shell code, network request, reconnaissance, or arbitrary path traversal is present. The skill does create a medium-severity privacy risk by persisting confidential contract terms without an explicit consent or retention check.

2
Files scanned
606
Lines analyzed
4
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
Persistent Storage of Confidential Contract Terms
The skill directs agents to persist drafts, final rates, usage rights, and exclusivity terms in memory and an events log without an explicit consent or retention check.
The instructions explicitly require reading prior creator records and writing contract terms to three persistent locations. No consent, redaction, retention, or access-control step is stated.
Audited by: codex

Jul 7, 2026, 06:08 AM

The static findings are false positives caused by Markdown formatting, repository links, memory-path documentation, and homepage metadata. I found no evidence of prompt injection, command execution, data exfiltration, unauthorized network behavior, or malicious filesystem traversal in SKILL.md or references/templates.md.

2
Files scanned
606
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex

Jul 6, 2026, 04:21 PM

The static findings are false positives caused by Markdown links, code fences, homepage metadata, and ordinary contract template language. No command execution, unsafe network behavior, prompt injection, or malicious data-exfiltration intent was found in SKILL.md or references/templates.md.

2
Files scanned
606
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex

Jul 4, 2026, 03:53 PM

The static findings are false positives caused by Markdown code fences, static repository links, metadata URLs, and ordinary contract terminology. I found no evidence of executable commands, arbitrary path traversal, network exfiltration, reconnaissance behavior, or prompt-injection text in the reviewed files.

2
Files scanned
606
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex