Audit History
list-hygiene-monitor - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 27, 2026, 11:22 AM | No confirmed findings | 1 | No capability change |
| v8 | Jul 13, 2026, 01:58 PM | No confirmed findings | 1 | No capability change |
| v7 | Jul 13, 2026, 01:58 PM | No confirmed findings | 1 | No capability change |
| v6 | Jul 12, 2026, 12:51 PM | 1 confirmed | 1 | No capability change |
| v5 | Jul 10, 2026, 11:13 AM | No confirmed findings | 2 | No capability change |
| v4 | Jul 9, 2026, 12:04 PM | No confirmed findings | 1 | No capability change |
| v3 | Jul 6, 2026, 05:46 PM | No confirmed findings | 1 | No capability change |
| v2 | Jul 6, 2026, 05:46 PM | No confirmed findings | 1 | No capability change |
| v1 | Jul 4, 2026, 04:11 PM | No confirmed findings | 1 | Baseline |
Jul 27, 2026, 11:22 AM
Most static findings are false positives caused by Markdown links and code formatting. One instruction runs local ESP connector and ledger commands; it is legitimate functionality but should execute only with user confirmation and validated values.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (27)
βοΈ External commands (28)
π Network access (2)
Jul 13, 2026, 01:58 PM
Fifty-six detections are false positives caused by Markdown backticks, repository-relative links, fixed memory paths, and homepage metadata. One medium-risk command pattern is confirmed: SKILL.md line 52 places the user-provided list identifier into shell examples without quoting. No evidence found of prompt injection, secret exfiltration, or an unauthorized external destination.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (27)
βοΈ External commands (28)
π Network access (2)
Jul 13, 2026, 01:58 PM
Fifty-six detections are false positives caused by Markdown backticks, repository-relative links, fixed memory paths, and homepage metadata. One medium-risk command pattern is confirmed: SKILL.md line 52 places the user-provided list identifier into shell examples without quoting. No evidence found of prompt injection, secret exfiltration, or an unauthorized external destination.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (27)
βοΈ External commands (28)
π Network access (2)
Jul 12, 2026, 12:51 PM
Most static findings are false positives caused by Markdown code formatting and relative documentation links. One instruction executes bundled Python connector commands against live email data, and saved worklists may retain sensitive subscriber information.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (27)
βοΈ External commands (28)
π Network access (2)
Jul 10, 2026, 11:13 AM
Most findings are false positives caused by Markdown formatting and fixed repository-relative links. Two findings are confirmed: line 52 uses an unquoted user-derived command argument, and line 70 creates a save path from an unsanitized value. No prompt injection or malicious exfiltration intent was found.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (27)
βοΈ External commands (27)
π Network access (2)
Jul 9, 2026, 12:04 PM
Most static findings are false positives from markdown links, code fences, and inline labels, not executable traversal or shell behavior. One confirmed issue remains: SKILL.md line 52 recommends optional Python connector commands that execute local scripts and may access ESP subscriber data.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (27)
βοΈ External commands (27)
π Network access (2)
Jul 6, 2026, 05:46 PM
Most static findings are false positives from Markdown relative links, prompt examples, inline labels, or homepage metadata. One confirmed medium-risk finding remains: SKILL.md line 52 tells the agent to run optional connector commands that can access ESP subscriber data and write ledger metrics. No evidence found for prompt injection, malicious exfiltration intent, or hidden business-logic abuse.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (27)
βοΈ External commands (27)
π Network access (2)
Jul 6, 2026, 05:46 PM
Most static findings are false positives from Markdown relative links, prompt examples, inline labels, or homepage metadata. One confirmed medium-risk finding remains: SKILL.md line 52 tells the agent to run optional connector commands that can access ESP subscriber data and write ledger metrics. No evidence found for prompt injection, malicious exfiltration intent, or hidden business-logic abuse.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
π Filesystem access (27)
βοΈ External commands (27)
π Network access (2)
Jul 4, 2026, 04:11 PM
Most static findings are false positives from Markdown code spans and repo-relative links, not executable Ruby backticks or path traversal. One medium finding remains confirmed because the skill documents optional python3 connector commands that read ESP subscriber and event data.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.