Audit History
talking-head-recut - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 19, 2026, 11:18 AM | 1 confirmed | 1 | No capability change |
| v4 | Jul 10, 2026, 07:32 PM | 1 confirmed | 0 | No capability change |
| v3 | Jul 8, 2026, 04:20 AM | 1 confirmed | 0 | No capability change |
| v2 | Jul 6, 2026, 02:51 PM | 1 confirmed | 0 | No capability change |
| v1 | Jul 3, 2026, 11:58 AM | No confirmed findings | 0 | Baseline |
Jul 19, 2026, 11:18 AM
One confirmed issue instructs unattended execution of an npx skill-update command without user approval. The remaining static matches are false positives caused by Markdown backticks, static CSS/reference content, local test code, and the bundled minified GSAP library.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚡ Contains scripts (2)
⚙️ External commands (50)
🌐 Network access (3)
📁 Filesystem access (4)
Jul 10, 2026, 07:32 PM
The static score is dominated by false matches on Markdown backticks, CSS borders, valid WOFF2 fonts, and the minified GSAP distribution. One high-confidence semantic risk remains: the skill orders an unpinned npx package update to run silently without user consent.
Confirmed security concerns (1)
Risk Factors
⚡ Contains scripts (2)
⚙️ External commands (50)
🌐 Network access (3)
📁 Filesystem access (2)
Jul 8, 2026, 04:20 AM
Most static hits are false positives from Markdown inline code, CSS border declarations, and a bundled minified GSAP library. The real security concern is operational: the skill asks the agent to run local CLI tools, including npx HyperFrames and ffmpeg/ffprobe, against user media. No prompt injection attempt or credential exfiltration instructions were found in the reviewed files.
Confirmed security concerns (1)
Risk Factors
⚡ Contains scripts (2)
⚙️ External commands (299)
🌐 Network access (3)
📁 Filesystem access (1)
Jul 6, 2026, 02:51 PM
Most static findings are false positives caused by Markdown formatting, CSS design references, WOFF2 font assets, and a minified GSAP vendor bundle. No prompt injection, credential exfiltration, or malicious payload intent was found. One medium semantic risk remains because the workflow executes unpinned npx hyperframes commands.
Confirmed security concerns (1)
Risk Factors
⚡ Contains scripts (2)
⚙️ External commands (299)
🌐 Network access (3)
📁 Filesystem access (1)
Jul 3, 2026, 11:58 AM
Manual adjudication found the static findings to be false positives caused by markdown examples, static HTML references, bundled fonts, and a minified GSAP browser library. No prompt injection, credential access, data exfiltration, or malicious command behavior was found in the reviewed context.