Audit History
email-quality-auditor - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 26, 2026, 10:14 AM | No confirmed findings | 0 | No capability change |
| v6 | Jul 26, 2026, 10:14 AM | No confirmed findings | 0 | No capability change |
| v5 | Jul 13, 2026, 01:23 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 13, 2026, 01:23 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 12, 2026, 12:09 PM | No confirmed findings | 1 | No capability change |
| v2 | Jul 6, 2026, 04:52 PM | 2 confirmed | 3 | No capability change |
| v1 | Jul 4, 2026, 04:03 PM | No confirmed findings | 0 | Baseline |
Jul 26, 2026, 10:14 AM
All 34 static findings are false positives caused by Markdown backticks, fixed local reference links, and homepage metadata. The reviewed instructions emphasize evidence-based email audits, prohibit autonomous sending and provider changes, and require explicit authorization before persistence. No prompt injection, exfiltration intent, or user-controlled command or path execution was found.
Risk Factors
⚙️ External commands (22)
🌐 Network access (2)
📁 Filesystem access (10)
Jul 26, 2026, 10:14 AM
All 34 static findings are false positives caused by Markdown backticks, fixed local reference links, and homepage metadata. The reviewed instructions emphasize evidence-based email audits, prohibit autonomous sending and provider changes, and require explicit authorization before persistence. No prompt injection, exfiltration intent, or user-controlled command or path execution was found.
Risk Factors
⚙️ External commands (22)
🌐 Network access (2)
📁 Filesystem access (10)
Jul 13, 2026, 01:23 PM
All 33 static alerts were adjudicated as false positives. The evidence consists of Markdown syntax, fixed repository references, metadata URLs, and a fixed local Git lookup without user-controlled arguments. No semantic threat or prompt injection was found.
Risk Factors
⚙️ External commands (21)
🌐 Network access (2)
📁 Filesystem access (10)
Jul 13, 2026, 01:23 PM
All 33 static alerts were adjudicated as false positives. The evidence consists of Markdown syntax, fixed repository references, metadata URLs, and a fixed local Git lookup without user-controlled arguments. No semantic threat or prompt injection was found.
Risk Factors
⚙️ External commands (21)
🌐 Network access (2)
📁 Filesystem access (10)
Jul 12, 2026, 12:09 PM
Most static findings are Markdown formatting, metadata URLs, fixed documentation links, or a controlled Git command without user-controlled arguments. The direct instruction to read parent-directory references crosses the packaged skill boundary and remains a confirmed filesystem concern.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (21)
🌐 Network access (2)
📁 Filesystem access (10)
Jul 6, 2026, 04:52 PM
Most static alerts are false positives from Markdown backticks and fixed relative documentation links. Confirmed risks are limited to optional connector command use, a runtime GitHub reference fetch, mutable remote instruction dependencies, and persistent audit artifacts.
Confirmed security concerns (2)
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (52)
🌐 Network access (3)
📁 Filesystem access (31)
Jul 4, 2026, 04:03 PM
The static findings are false positives caused by Markdown code spans, repository-relative links, fixed memory paths, and documentation URLs. Line 89 documents constrained, read-only helper commands for deliverability evidence; I found no prompt injection, exfiltration, destructive command, or path traversal intent.