Audit History
conversion-signal-qa - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 26, 2026, 10:07 AM | No confirmed findings | 0 | No capability change |
| v6 | Jul 26, 2026, 10:07 AM | No confirmed findings | 0 | No capability change |
| v5 | Jul 13, 2026, 12:44 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 13, 2026, 12:44 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 12, 2026, 11:46 AM | No confirmed findings | 0 | No capability change |
| v2 | Jul 6, 2026, 04:25 PM | No confirmed findings | 0 | No capability change |
| v1 | Jul 4, 2026, 04:05 PM | 1 confirmed | 0 | Baseline |
Jul 26, 2026, 10:07 AM
All 39 static findings are false positives caused by Markdown formatting, relative documentation links, and marketing terminology. The skill contains no executable commands, network requests, path traversal behavior, prompt-injection language, or evidence of data exfiltration. It explicitly treats pasted exports as untrusted and requires consent before saving results.
Risk Factors
π Filesystem access (13)
βοΈ External commands (17)
π Network access (2)
Jul 26, 2026, 10:07 AM
All 39 static findings are false positives caused by Markdown formatting, relative documentation links, and marketing terminology. The skill contains no executable commands, network requests, path traversal behavior, prompt-injection language, or evidence of data exfiltration. It explicitly treats pasted exports as untrusted and requires consent before saving results.
Risk Factors
π Filesystem access (13)
βοΈ External commands (17)
π Network access (2)
Jul 13, 2026, 12:44 PM
All 39 static findings are false positives caused by Markdown links, code fences, inline code, slash-separated labels, or repository metadata. The skill contains no executable commands, network requests, path traversal operations, reconnaissance behavior, or prompt injection.
Risk Factors
π Filesystem access (13)
βοΈ External commands (17)
π Network access (2)
Jul 13, 2026, 12:44 PM
All 39 static findings are false positives caused by Markdown links, code fences, inline code, slash-separated labels, or repository metadata. The skill contains no executable commands, network requests, path traversal operations, reconnaissance behavior, or prompt injection.
Risk Factors
π Filesystem access (13)
βοΈ External commands (17)
π Network access (2)
Jul 12, 2026, 11:46 AM
All 39 static findings are false positives caused by Markdown formatting, relative documentation links, marketing terminology, and homepage metadata. The skill contains no executable code, network request, prompt injection, or unsafe path handling, and consent is required before saving results.
Risk Factors
π Filesystem access (13)
βοΈ External commands (17)
π Network access (2)
Jul 6, 2026, 04:25 PM
No confirmed malicious behavior was found. Static findings are false positives caused by Markdown links, fenced prompt examples, metadata URLs, and marketing analytics terms.
Risk Factors
π Filesystem access (13)
βοΈ External commands (17)
π Network access (2)
Jul 4, 2026, 04:05 PM
The static findings are false positives caused by Markdown links, fenced prompt examples, inline-code formatting, and repository metadata URLs. No prompt-injection attempt, hidden command execution, runtime network call, or malicious exfiltration intent was found. One medium semantic issue remains: the optional memory save path uses a <topic> filename placeholder without an explicit sanitization rule.