Audit History
report-generator - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 12, 2026, 01:48 PM | 1 confirmed | 0 | No capability change |
| v4 | Jul 12, 2026, 01:48 PM | 1 confirmed | 0 | No capability change |
| v3 | Jul 7, 2026, 06:37 AM | No confirmed findings | 0 | No capability change |
| v2 | Jul 6, 2026, 06:53 PM | 1 confirmed | 0 | No capability change |
| v1 | Jul 4, 2026, 04:20 PM | No confirmed findings | 0 | Baseline |
Jul 12, 2026, 01:48 PM
All 38 static findings are false positives caused by Markdown links, code fences, inline code, metadata URLs, or ordinary reporting language. One medium semantic risk remains because the skill directs agents to persist campaign reports and selected metrics in shared memory without requesting confirmation.
Confirmed security concerns (1)
Risk Factors
π Filesystem access (16)
βοΈ External commands (15)
π Network access (2)
Jul 12, 2026, 01:48 PM
All 38 static findings are false positives caused by Markdown links, code fences, inline code, metadata URLs, or ordinary reporting language. One medium semantic risk remains because the skill directs agents to persist campaign reports and selected metrics in shared memory without requesting confirmation.
Confirmed security concerns (1)
Risk Factors
π Filesystem access (16)
βοΈ External commands (15)
π Network access (2)
Jul 7, 2026, 06:37 AM
No confirmed malicious behavior was found in the reviewed files. Static findings are explained by Markdown code fences, inline formatting, source metadata URLs, relative documentation links, and fixed memory output paths.
Risk Factors
π Filesystem access (16)
βοΈ External commands (15)
π Network access (2)
Jul 6, 2026, 06:53 PM
Static findings were false positives after context review. The apparent command, network, reconnaissance, and traversal signals are Markdown links, metadata, examples, or report-writing prose. One medium semantic risk remains because the dynamic report filename lacks an explicit slugging and path containment rule.
Confirmed security concerns (1)
Risk Factors
π Filesystem access (20)
βοΈ External commands (15)
π Network access (2)
Jul 4, 2026, 04:20 PM
All static findings were adjudicated as false positives caused by Markdown links, code fences, inline backticks, homepage metadata, and report-template wording. I found no evidence of prompt injection, credential access, command execution, unsafe network calls, or malicious file-system behavior in the reviewed files.