Audit History
email-render-builder - 10 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v10 Latest | Jul 26, 2026, 10:17 AM | No confirmed findings | 2 | No capability change |
| v9 | Jul 26, 2026, 10:17 AM | No confirmed findings | 2 | No capability change |
| v8 | Jul 13, 2026, 01:28 PM | No confirmed findings | 0 | No capability change |
| v7 | Jul 13, 2026, 01:28 PM | No confirmed findings | 0 | No capability change |
| v6 | Jul 12, 2026, 12:12 PM | No confirmed findings | 1 | No capability change |
| v5 | Jul 10, 2026, 10:48 AM | 1 confirmed | 1 | No capability change |
| v4 | Jul 9, 2026, 11:40 AM | No confirmed findings | 1 | No capability change |
| v3 | Jul 6, 2026, 04:57 PM | No confirmed findings | 1 | No capability change |
| v2 | Jul 6, 2026, 04:57 PM | No confirmed findings | 1 | No capability change |
| v1 | Jul 4, 2026, 04:06 PM | No confirmed findings | 1 | Baseline |
Jul 26, 2026, 10:17 AM
Most static matches are false positives caused by Markdown fences, relative documentation links, and email-client terminology. Two operational behaviors remain: an optional live render-test email command and a user-confirmed local result save; neither shows malicious intent, but both require confirmation and path validation.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (19)
βοΈ External commands (16)
π Network access (2)
Jul 26, 2026, 10:17 AM
Most static matches are false positives caused by Markdown fences, relative documentation links, and email-client terminology. Two operational behaviors remain: an optional live render-test email command and a user-confirmed local result save; neither shows malicious intent, but both require confirmation and path validation.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (19)
βοΈ External commands (16)
π Network access (2)
Jul 13, 2026, 01:28 PM
All 49 static findings are false positives caused by Markdown syntax, relative documentation links, client names, and one documented render-test command. The skill contains no executable scripts and explicitly treats pasted markup as untrusted; no prompt injection or exfiltration intent was found.
Risk Factors
π Filesystem access (19)
βοΈ External commands (16)
π Network access (2)
Jul 13, 2026, 01:28 PM
All 49 static findings are false positives caused by Markdown syntax, relative documentation links, client names, and one documented render-test command. The skill contains no executable scripts and explicitly treats pasted markup as untrusted; no prompt injection or exfiltration intent was found.
Risk Factors
π Filesystem access (19)
βοΈ External commands (16)
π Network access (2)
Jul 12, 2026, 12:12 PM
Most static alerts are false positives caused by Markdown backticks, relative documentation links, HTML terms, and email-client compatibility guidance. The Resend test-send instruction is a confirmed external-command capability with an optional live network action, although its stated scope is limited to user-owned test inboxes.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (19)
βοΈ External commands (16)
π Network access (2)
Jul 10, 2026, 10:48 AM
Most static alerts are false positives caused by Markdown backticks, repository-relative documentation links, and email-client terminology. The optional Resend command can execute a local connector and send email with the live flag, while the skill also directs persistent memory updates without an explicit approval gate.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (19)
βοΈ External commands (16)
π Network access (2)
Jul 9, 2026, 11:40 AM
Most static findings are false positives from markdown links, metadata URLs, client names, and inline documentation. One confirmed medium-risk item remains: a documented Resend render-test command can perform live networked email sending. No prompt injection, data exfiltration intent, or malicious business logic was found in the reviewed files.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (19)
βοΈ External commands (16)
π Network access (2)
Jul 6, 2026, 04:57 PM
Most static findings are false positives caused by markdown links, fenced examples, fixed memory paths, and email-client terminology. One medium-risk finding is confirmed: the skill includes an optional python3 Resend connector command that can perform a live render-test send when explicitly requested.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (19)
βοΈ External commands (16)
π Network access (2)
Jul 6, 2026, 04:57 PM
Most static findings are false positives caused by markdown links, fenced examples, fixed memory paths, and email-client terminology. One medium-risk finding is confirmed: the skill includes an optional python3 Resend connector command that can perform a live render-test send when explicitly requested.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (19)
βοΈ External commands (16)
π Network access (2)
Jul 4, 2026, 04:06 PM
Most static findings are false positives caused by Markdown links, inline code formatting, and email-client names used for render QA. One medium-risk finding remains confirmed because SKILL.md documents a live Resend test-send command that can send email through an ESP. No prompt-injection attempt, credential theft, or data-exfiltration intent was found in the reviewed files.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.