Audit History
slack-gif-creator - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 23, 2026, 04:11 PM | No confirmed findings | 0 | No capability change |
| v8 | Jul 10, 2026, 01:08 PM | No confirmed findings | 0 | No capability change |
| v7 | Jul 6, 2026, 09:15 AM | No confirmed findings | 0 | Contains scriptsExternal commands Filesystem access |
| v6 | Jun 29, 2026, 03:04 PM | 1 confirmed | 1 | Filesystem access Network accessContains scriptsExternal commands |
| v5 | Jan 17, 2026, 02:43 AM | No confirmed findings | 0 | No capability change |
| v4 | Jan 17, 2026, 02:43 AM | No confirmed findings | 0 | Network accessExternal commands Filesystem access |
| v3 | Jan 7, 2026, 01:29 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 7, 2026, 01:29 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 7, 2026, 01:29 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 04:11 PM
All 40 static findings are false positives caused by Markdown code formatting, ordinary Python imports, or benign descriptive text. The reviewed files contain no command substitution, dynamic loading, system reconnaissance, prompt injection, network access, secret access, or subprocess execution.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (36)
Jul 10, 2026, 01:08 PM
All 40 static findings are false positives caused by Markdown code formatting, ordinary Python imports, or benign descriptive text. The reviewed files contain no command substitution, dynamic loading, system reconnaissance, prompt injection, network access, secret access, or subprocess execution.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (36)
Jul 6, 2026, 09:15 AM
All 68 static findings were adjudicated as false positives after reviewing the cited files. The alerts come from Markdown code fences, normal Python imports, documentation text, or local GIF rendering logic; no prompt injection, command execution, reconnaissance, or network behavior was found.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (58)
Jun 29, 2026, 03:04 PM
Static analysis reported many high-risk patterns, but review found they are false positives from Markdown code fences, animation math terms, Apache license text, and documentation wording. No evidence found of network clients, command execution, credential access, dynamic eval, obfuscation, or prompt injection. The confirmed risk is limited local filesystem access for saving generated GIFs and validating existing GIF files.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
📁 Filesystem access (3)
Jan 17, 2026, 02:43 AM
All 122 static findings are FALSE POSITIVES. The scanner detected animation mathematics patterns (easing functions, trigonometric operations) and file validation operations, misinterpreting them as security threats. This is a legitimate GIF creation toolkit with no malicious intent.
Risk Factors
🌐 Network access (2)
⚡ Contains scripts (1)
⚙️ External commands (65)
Jan 17, 2026, 02:43 AM
All 122 static findings are FALSE POSITIVES. The scanner detected animation mathematics patterns (easing functions, trigonometric operations) and file validation operations, misinterpreting them as security threats. This is a legitimate GIF creation toolkit with no malicious intent.
Risk Factors
🌐 Network access (2)
⚡ Contains scripts (1)
⚙️ External commands (65)
Jan 7, 2026, 01:29 AM
This is a legitimate Python GIF creation toolkit. It only performs local image processing using standard libraries (Pillow, numpy, imageio). No network calls, no credential access, no persistence mechanisms, and no obfuscated code detected.
Risk Factors
📁 Filesystem access (2)
⚡ Contains scripts (2)
Jan 7, 2026, 01:29 AM
This is a legitimate Python GIF creation toolkit. It only performs local image processing using standard libraries (Pillow, numpy, imageio). No network calls, no credential access, no persistence mechanisms, and no obfuscated code detected.
Risk Factors
📁 Filesystem access (2)
⚡ Contains scripts (2)
Jan 7, 2026, 01:29 AM
This is a legitimate Python GIF creation toolkit. It only performs local image processing using standard libraries (Pillow, numpy, imageio). No network calls, no credential access, no persistence mechanisms, and no obfuscated code detected.