Audit History
email-creative-builder - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 26, 2026, 10:13 AM | No confirmed findings | 0 | No capability change |
| v6 | Jul 26, 2026, 10:13 AM | No confirmed findings | 0 | No capability change |
| v5 | Jul 13, 2026, 01:19 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 13, 2026, 01:19 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 12, 2026, 12:07 PM | No confirmed findings | 0 | No capability change |
| v2 | Jul 6, 2026, 04:49 PM | No confirmed findings | 0 | No capability change |
| v1 | Jul 4, 2026, 04:00 PM | No confirmed findings | 0 | Baseline |
Jul 26, 2026, 10:13 AM
All 42 static matches are false positives. Relative Markdown links and documented paths were labeled as path traversal, while Markdown backticks were labeled as shell execution. The homepage URLs are metadata only, and no prompt injection, data exfiltration, or executable behavior was found.
Risk Factors
π Filesystem access (23)
βοΈ External commands (14)
π Network access (2)
Jul 26, 2026, 10:13 AM
All 42 static matches are false positives. Relative Markdown links and documented paths were labeled as path traversal, while Markdown backticks were labeled as shell execution. The homepage URLs are metadata only, and no prompt injection, data exfiltration, or executable behavior was found.
Risk Factors
π Filesystem access (23)
βοΈ External commands (14)
π Network access (2)
Jul 13, 2026, 01:19 PM
All 42 static findings are false positives caused by Markdown links, code formatting, path templates, or repository metadata URLs. The skill contains no executable code and includes explicit safeguards for untrusted input, claim approval, sending, and file saves. No malicious intent or prompt injection was found.
Risk Factors
π Filesystem access (23)
βοΈ External commands (14)
π Network access (2)
Jul 13, 2026, 01:19 PM
All 42 static findings are false positives caused by Markdown links, code formatting, path templates, or repository metadata URLs. The skill contains no executable code and includes explicit safeguards for untrusted input, claim approval, sending, and file saves. No malicious intent or prompt injection was found.
Risk Factors
π Filesystem access (23)
βοΈ External commands (14)
π Network access (2)
Jul 12, 2026, 12:07 PM
All 42 static findings are false positives caused by Markdown links, code fences, inline code, metadata URLs, and ordinary email terminology. The skill contains no executable implementation, prompt injection attempt, credential access, covert network request, or unsafe path construction.
Risk Factors
π Filesystem access (23)
βοΈ External commands (14)
π Network access (2)
Jul 6, 2026, 04:49 PM
Manual review found that the static findings are false positives from Markdown links, inline code formatting, prompt examples, and repository metadata. No executable shell commands, malicious path traversal, data exfiltration, system reconnaissance, or prompt injection attempts were found in the reviewed files.
Risk Factors
π Filesystem access (25)
βοΈ External commands (17)
π Network access (2)
Jul 4, 2026, 04:00 PM
All static findings were reviewed against the Markdown source files. The filesystem, command, blocker, and network alerts are false positives caused by relative documentation links, Markdown backticks, bounded memory paths, and metadata URLs. No prompt injection, data exfiltration, command execution, or unsafe filesystem intent was found.