๐Ÿ“ฆ

Audit History

executor-discovery - 1 audit

Oct 5, 2026, 05:17 PM

Of 130 static findings, 129 concern Markdown syntax, fixed relative references, or legitimate workflow operations. One confirmed risk concerns binding the visual server to all interfaces, exposing token-protected HTTP beyond localhost. No evidence found of prompt injection or deliberate exfiltration; referenced scripts are absent from the reviewed files, so their implementations remain unverified.

2
Files scanned
875
Lines analyzed
4
Review items
0
False positives ignored
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Medium
Hardcoded IP address
--host 0.0.0.0 \
Binding to 0.0.0.0 exposes the visual server on every IPv4 interface. The documented HTTP URL lacks transport encryption; token authentication mitigates but does not eliminate exposure.

Risk Factors

Audited by: codex