Audit History
email-sequence-designer - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 26, 2026, 10:18 AM | No confirmed findings | 2 | No capability change |
| v6 | Jul 26, 2026, 10:18 AM | No confirmed findings | 2 | No capability change |
| v5 | Jul 13, 2026, 01:33 PM | No confirmed findings | 1 | No capability change |
| v4 | Jul 13, 2026, 01:33 PM | No confirmed findings | 1 | No capability change |
| v3 | Jul 12, 2026, 12:16 PM | No confirmed findings | 1 | No capability change |
| v2 | Jul 6, 2026, 05:01 PM | 1 confirmed | 1 | No capability change |
| v1 | Jul 4, 2026, 04:00 PM | No confirmed findings | 1 | Baseline |
Jul 26, 2026, 10:18 AM
Most static findings are false positives caused by Markdown code fences and relative documentation links. Two risks remain: the Resend shell example lacks safe handling for supplied values, and the save filename is derived from a flow or goal without a stated sanitization rule.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (14)
π Network access (2)
π Filesystem access (29)
π Env variables (1)
Jul 26, 2026, 10:18 AM
Most static findings are false positives caused by Markdown code fences and relative documentation links. Two risks remain: the Resend shell example lacks safe handling for supplied values, and the save filename is derived from a flow or goal without a stated sanitization rule.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (14)
π Network access (2)
π Filesystem access (29)
π Env variables (1)
Jul 13, 2026, 01:33 PM
One finding is confirmed: line 52 directs execution of a connector command that can schedule a live email broadcast. The other 45 findings are false positives from Markdown formatting, links, metadata, and a constrained output path. No prompt injection, credential theft, obfuscation, or malicious intent was found.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (14)
π Network access (2)
π Filesystem access (29)
π Env variables (1)
Jul 13, 2026, 01:33 PM
One finding is confirmed: line 52 directs execution of a connector command that can schedule a live email broadcast. The other 45 findings are false positives from Markdown formatting, links, metadata, and a constrained output path. No prompt injection, credential theft, obfuscation, or malicious intent was found.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (14)
π Network access (2)
π Filesystem access (29)
π Env variables (1)
Jul 12, 2026, 12:16 PM
Most detections are Markdown fences, inline code, metadata URLs, and documentation links, so they do not execute commands, access URLs, traverse files, or read environment data. The Resend activation instruction at SKILL.md line 52 is a real external command with a live email-sending side effect, but it requires a preview, user confirmation, and consent checks. No prompt injection or covert exfiltration intent was found.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (14)
π Network access (2)
π Filesystem access (29)
π Env variables (1)
Jul 6, 2026, 05:01 PM
Most static findings are false positives caused by Markdown fences, inline code, homepage URLs, and relative documentation links. The confirmed issue is the Resend connector command that can create and schedule email broadcasts. No prompt-injection language was found in SKILL.md.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (12)
π Network access (2)
π Filesystem access (29)
π Env variables (1)
Jul 4, 2026, 04:00 PM
Most static findings are false positives from Markdown code fences, inline paths, relative documentation links, and GitHub metadata. One medium risk remains: SKILL.md line 52 instructs agents to run a Resend connector that can schedule or send email when rerun with --live. No prompt injection, credential exfiltration, or malicious intent was found.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.