Audit History
list-segment-builder - 6 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v6 Latest | Jul 26, 2026, 10:29 AM | No confirmed findings | 1 | No capability change |
| v5 | Jul 13, 2026, 02:02 PM | No confirmed findings | 1 | No capability change |
| v4 | Jul 13, 2026, 02:02 PM | No confirmed findings | 1 | No capability change |
| v3 | Jul 12, 2026, 12:55 PM | 1 confirmed | 1 | No capability change |
| v2 | Jul 6, 2026, 05:50 PM | 1 confirmed | 1 | No capability change |
| v1 | Jul 4, 2026, 04:14 PM | No confirmed findings | 1 | Baseline |
Jul 26, 2026, 10:29 AM
Most static findings are false positives caused by Markdown code fences, inline code, and relative documentation links. One documented Resend command can perform a live suppression update when invoked with --live; it should require a clear user confirmation immediately before execution. No prompt-injection or data-exfiltration intent was found.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (18)
🌐 Network access (2)
Jul 13, 2026, 02:02 PM
Forty static alerts are false positives caused by Markdown fences, inline code, fixed documentation links, and GitHub metadata. One command is confirmed because SKILL.md instructs the agent to run a Resend connector that can perform a live suppression mutation.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (18)
🌐 Network access (2)
Jul 13, 2026, 02:02 PM
Forty static alerts are false positives caused by Markdown fences, inline code, fixed documentation links, and GitHub metadata. One command is confirmed because SKILL.md instructs the agent to run a Resend connector that can perform a live suppression mutation.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (18)
🌐 Network access (2)
Jul 12, 2026, 12:55 PM
Forty static alerts are false positives caused by Markdown fences, inline code, metadata URLs, and fixed relative links. One connector command is confirmed, and its live suppression mode lacks explicit per-action approval.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (18)
🌐 Network access (2)
Jul 6, 2026, 05:50 PM
Most static findings are false positives from Markdown code fences, inline file paths, and relative documentation links. One external command is confirmed because line 52 documents a Python connector command that can perform live Resend suppression with --live. No prompt injection or data-exfiltration intent was found in SKILL.md.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (18)
🌐 Network access (2)
Jul 4, 2026, 04:14 PM
Most static findings are Markdown false positives from code fences, inline path literals, or relative repository links. One real medium-risk issue remains: the Resend connector command can read ESP data and mutate suppression state when run with --live, although the skill documents dry-run behavior. No prompt injection attempt or malicious exfiltration intent was found in SKILL.md.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.