Audit History
fatigue-frequency-manager - 10 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v10 Latest | Jul 26, 2026, 10:19 AM | No confirmed findings | 1 | No capability change |
| v9 | Jul 26, 2026, 10:19 AM | No confirmed findings | 1 | No capability change |
| v8 | Jul 13, 2026, 01:37 PM | No confirmed findings | 2 | No capability change |
| v7 | Jul 13, 2026, 01:37 PM | No confirmed findings | 2 | No capability change |
| v6 | Jul 12, 2026, 12:23 PM | No confirmed findings | 1 | No capability change |
| v5 | Jul 10, 2026, 10:52 AM | No confirmed findings | 1 | No capability change |
| v4 | Jul 9, 2026, 11:44 AM | No confirmed findings | 1 | No capability change |
| v3 | Jul 6, 2026, 05:12 PM | No confirmed findings | 2 | No capability change |
| v2 | Jul 6, 2026, 05:12 PM | No confirmed findings | 2 | No capability change |
| v1 | Jul 4, 2026, 04:10 PM | No confirmed findings | 1 | Baseline |
Jul 26, 2026, 10:19 AM
Most static findings are false positives caused by Markdown formatting, fixed documentation links, and metadata URLs. One command template is confirmed: it places a user-controlled ad-set placeholder directly in a shell command, creating a command-injection risk if executed literally. The skill otherwise instructs agents to treat campaign exports as untrusted data and requires confirmation before saving results.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (14)
π Network access (2)
π Filesystem access (14)
Jul 26, 2026, 10:19 AM
Most static findings are false positives caused by Markdown formatting, fixed documentation links, and metadata URLs. One command template is confirmed: it places a user-controlled ad-set placeholder directly in a shell command, creating a command-injection risk if executed literally. The skill otherwise instructs agents to treat campaign exports as untrusted data and requires confirmation before saving results.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (14)
π Network access (2)
π Filesystem access (14)
Jul 13, 2026, 01:37 PM
Most static findings are false positives caused by Markdown code spans and fixed relative documentation links. One command template passes an unquoted ad-set value to a shell command, and the save template incorporates an ad-set value into a file path. These two instructions require input validation and safe argument handling before use.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (14)
π Network access (2)
π Filesystem access (14)
Jul 13, 2026, 01:37 PM
Most static findings are false positives caused by Markdown code spans and fixed relative documentation links. One command template passes an unquoted ad-set value to a shell command, and the save template incorporates an ad-set value into a file path. These two instructions require input validation and safe argument handling before use.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (14)
π Network access (2)
π Filesystem access (14)
Jul 12, 2026, 12:23 PM
One command invocation is confirmed because an unquoted ad-set value could enable shell injection. All other detections are benign Markdown, metadata, or fixed references.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (14)
π Network access (2)
π Filesystem access (14)
Jul 10, 2026, 10:52 AM
Most alerts are false positives from Markdown syntax, documentation links, and repository metadata URLs. One medium-risk ledger command remains confirmed. It places a user-derived ad-set name into a shell example without explicit validation or safe argument handling.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (14)
π Network access (2)
π Filesystem access (14)
Jul 9, 2026, 11:44 AM
Most static findings are false positives caused by markdown backticks, repository URLs, and relative documentation links. One medium-risk command-use finding is confirmed because SKILL.md instructs running ledger.py with an ad-set argument that can originate from user input. No prompt injection, data exfiltration intent, or unauthorized network behavior was found in SKILL.md.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (14)
π Network access (2)
π Filesystem access (14)
Jul 6, 2026, 05:12 PM
Most static findings are false positives from Markdown code spans, fenced examples, metadata URLs, and static repository links. I confirmed one external command concern for the ledger.py example and one filesystem concern for saving files with a user-derived ad-set name.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (14)
π Network access (2)
π Filesystem access (14)
Jul 6, 2026, 05:12 PM
Most static findings are false positives from Markdown code spans, fenced examples, metadata URLs, and static repository links. I confirmed one external command concern for the ledger.py example and one filesystem concern for saving files with a user-derived ad-set name.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
βοΈ External commands (14)
π Network access (2)
π Filesystem access (14)
Jul 4, 2026, 04:10 PM
Most static detections are false positives caused by Markdown formatting, repository links, and relative documentation links in SKILL.md. One medium external-command concern remains on line 57 because the skill tells agents to run a local Python helper with a user-provided ad-set placeholder. No prompt injection, data exfiltration intent, or unauthorized network behavior was found.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.