Audit History
contract-helper - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 26, 2026, 10:05 AM | No confirmed findings | 0 | No capability change |
| v7 | Jul 26, 2026, 10:05 AM | No confirmed findings | 0 | No capability change |
| v6 | Jul 13, 2026, 12:40 PM | 1 confirmed | 0 | No capability change |
| v5 | Jul 13, 2026, 12:40 PM | 1 confirmed | 0 | No capability change |
| v4 | Jul 12, 2026, 11:43 AM | 1 confirmed | 0 | No capability change |
| v3 | Jul 7, 2026, 06:08 AM | No confirmed findings | 0 | No capability change |
| v2 | Jul 6, 2026, 04:21 PM | No confirmed findings | 0 | No capability change |
| v1 | Jul 4, 2026, 03:53 PM | No confirmed findings | 0 | Baseline |
Jul 26, 2026, 10:05 AM
All 36 static findings are false positives caused by Markdown syntax, documentation links, and contract-template language. The skill provides legal drafting guidance and documents optional integrations, but contains no executable commands, network requests, or prompt-injection content. Contract data should still be handled under the userβs applicable privacy and retention policies.
Risk Factors
π Filesystem access (17)
βοΈ External commands (11)
π Network access (2)
Jul 26, 2026, 10:05 AM
All 36 static findings are false positives caused by Markdown syntax, documentation links, and contract-template language. The skill provides legal drafting guidance and documents optional integrations, but contains no executable commands, network requests, or prompt-injection content. Contract data should still be handled under the userβs applicable privacy and retention policies.
Risk Factors
π Filesystem access (17)
βοΈ External commands (11)
π Network access (2)
Jul 13, 2026, 12:40 PM
All 36 static findings are false positives caused by Markdown syntax, fixed repository links, marketing terms, and metadata URLs. No reviewed content executes commands, resolves user-controlled traversal paths, performs reconnaissance, or sends network requests. One semantic concern remains: the skill stores sensitive signed terms in durable memory without explicit confirmation.
Confirmed security concerns (1)
Risk Factors
π Filesystem access (17)
βοΈ External commands (11)
π Network access (2)
Jul 13, 2026, 12:40 PM
All 36 static findings are false positives caused by Markdown syntax, fixed repository links, marketing terms, and metadata URLs. No reviewed content executes commands, resolves user-controlled traversal paths, performs reconnaissance, or sends network requests. One semantic concern remains: the skill stores sensitive signed terms in durable memory without explicit confirmation.
Confirmed security concerns (1)
Risk Factors
π Filesystem access (17)
βοΈ External commands (11)
π Network access (2)
Jul 12, 2026, 11:43 AM
All 36 static findings are false positives caused by Markdown syntax, relative documentation links, metadata URLs, and ordinary marketing language. No executable shell code, network request, reconnaissance, or arbitrary path traversal is present. The skill does create a medium-severity privacy risk by persisting confidential contract terms without an explicit consent or retention check.
Confirmed security concerns (1)
Risk Factors
π Filesystem access (17)
βοΈ External commands (11)
π Network access (2)
Jul 7, 2026, 06:08 AM
The static findings are false positives caused by Markdown formatting, repository links, memory-path documentation, and homepage metadata. I found no evidence of prompt injection, command execution, data exfiltration, unauthorized network behavior, or malicious filesystem traversal in SKILL.md or references/templates.md.
Risk Factors
π Filesystem access (17)
βοΈ External commands (11)
π Network access (2)
Jul 6, 2026, 04:21 PM
The static findings are false positives caused by Markdown links, code fences, homepage metadata, and ordinary contract template language. No command execution, unsafe network behavior, prompt injection, or malicious data-exfiltration intent was found in SKILL.md or references/templates.md.
Risk Factors
π Filesystem access (17)
βοΈ External commands (11)
π Network access (2)
Jul 4, 2026, 03:53 PM
The static findings are false positives caused by Markdown code fences, static repository links, metadata URLs, and ordinary contract terminology. I found no evidence of executable commands, arbitrary path traversal, network exfiltration, reconnaissance behavior, or prompt-injection text in the reviewed files.