📦

Audit History

competitive-ads-extractor - 7 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v7 LatestJul 6, 2026, 08:04 AM No confirmed findings0No capability change
v6 Jul 6, 2026, 08:04 AM No confirmed findings0External commands Network accessFilesystem access
v5 Jun 29, 2026, 01:45 AM No confirmed findings0Network accessFilesystem access External commands
v4 Jan 16, 2026, 10:25 PM No confirmed findings0No capability change
v3 Jan 16, 2026, 10:25 PM No confirmed findings0External commands
v2 Jan 6, 2026, 07:27 AM No confirmed findings0No capability change
v1 Jan 6, 2026, 07:27 AM No confirmed findings0Baseline

Jul 6, 2026, 08:04 AM

The 21 static external-command findings are false positives caused by Markdown code fences in SKILL.md. No executable scripts, command invocation instructions, credential access, or prompt injection attempts were found in the analyzed file.

1
Files scanned
294
Lines analyzed
1
Review items
0
False positives ignored
Audited by: codex

Jul 6, 2026, 08:04 AM

The 21 static external-command findings are false positives caused by Markdown code fences in SKILL.md. No executable scripts, command invocation instructions, credential access, or prompt injection attempts were found in the analyzed file.

1
Files scanned
294
Lines analyzed
1
Review items
0
False positives ignored
Audited by: codex

Jun 29, 2026, 01:45 AM

Static command execution and weak cryptography findings were false positives from markdown examples and ordinary text. The skill is non-executable guidance, but it asks assistants to access public ad libraries and save extracted outputs, so publication should note network and filesystem use.

1
Files scanned
294
Lines analyzed
2
Review items
2
False positives ignored
Static false positives ignored (2)

These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.

Low
False Positive: Markdown Examples Flagged as Command Execution
The static analyzer matched fenced markdown prompt examples and sample output as Ruby shell backtick execution. These blocks contain natural language prompts and illustrative reports, not executable Ruby or shell code.
The matched locations are inside markdown code fences that show user prompts or expected output. No executable script, interpreter invocation, or command substitution syntax is present.
Low
False Positive: Weak Cryptography Keyword Match
The weak cryptography findings appear to match ordinary words in descriptive markdown, not calls to MD5, SHA1, DES, RC4, or other cryptographic APIs. No evidence found of cryptographic implementation or credential handling.
The cited lines are prose about ad analysis and ethical use. They contain no crypto library usage, hashing function, encryption mode, key material, or security-sensitive data flow.
Audited by: codex

Jan 16, 2026, 10:25 PM

This is a pure documentation skill containing only markdown prompts and guidance for marketing research. No executable code, scripts, network calls, or file system operations. The skill defines analytical prompts for understanding competitor ad strategies but relies entirely on the AI tool having appropriate browser or API tools available.

2
Files scanned
472
Lines analyzed
1
Review items
0
False positives ignored
Audited by: claude

Jan 16, 2026, 10:25 PM

This is a pure documentation skill containing only markdown prompts and guidance for marketing research. No executable code, scripts, network calls, or file system operations. The skill defines analytical prompts for understanding competitor ad strategies but relies entirely on the AI tool having appropriate browser or API tools available.

2
Files scanned
472
Lines analyzed
1
Review items
0
False positives ignored
Audited by: claude

Jan 6, 2026, 07:27 AM

This is a pure prompt-based skill containing only documentation and guidance. No executable code, scripts, network calls, or file system access. The skill defines how an AI assistant should analyze competitor ads but cannot take any actions itself - it relies on the AI tool having appropriate MCP tools available.

1
Files scanned
294
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 6, 2026, 07:27 AM

This is a pure prompt-based skill containing only documentation and guidance. No executable code, scripts, network calls, or file system access. The skill defines how an AI assistant should analyze competitor ads but cannot take any actions itself - it relies on the AI tool having appropriate MCP tools available.

1
Files scanned
294
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude