📦

Audit History

maxart-creative-studio - 5 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v5 LatestAug 7, 2026, 09:54 AM No confirmed findings0No capability change
v4 Jul 6, 2026, 02:58 PM No confirmed findings0No capability change
v3 Jul 6, 2026, 02:58 PM No confirmed findings0External commands
v2 Jun 30, 2026, 04:11 AM No confirmed findings1Network access
v1 Apr 9, 2026, 02:14 PM No confirmed findings0Baseline

Aug 7, 2026, 09:54 AM

All three static findings are false positives. The URL and Markdown reference are documentation, while the flagged prose does not perform system reconnaissance or external command execution.

2
Files scanned
98
Lines analyzed
2
Review items
0
False positives ignored

Risk Factors

⚙️ External commands (1)
🌐 Network access (1)
Audited by: codex

Jul 6, 2026, 02:58 PM

Reviewed six static findings in the cited files. All findings are false positives caused by markdown prose, an informational URL, and inline-code formatting rather than executable commands or unsafe network behavior. No semantic security findings or prompt injection attempts were found.

3
Files scanned
221
Lines analyzed
2
Review items
0
False positives ignored

Risk Factors

⚙️ External commands (1)
🌐 Network access (1)
Audited by: codex

Jul 6, 2026, 02:58 PM

Reviewed six static findings in the cited files. All findings are false positives caused by markdown prose, an informational URL, and inline-code formatting rather than executable commands or unsafe network behavior. No semantic security findings or prompt injection attempts were found.

3
Files scanned
221
Lines analyzed
2
Review items
0
False positives ignored

Risk Factors

⚙️ External commands (1)
🌐 Network access (1)
Audited by: codex

Jun 30, 2026, 04:11 AM

Static analysis reported weak cryptography, system reconnaissance, network URLs, and command execution indicators. Review found the cryptography, reconnaissance, and command findings are false positives from ordinary prompt prose and Markdown formatting. The only remaining concern is benign external links to MaxArt.ai and AI Dreamhub, with no executable network code found.

3
Files scanned
221
Lines analyzed
2
Review items
2
False positives ignored
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Low
Benign External Documentation Links
The hardcoded URLs are a README badge link and the declared MaxArt primary site. They do not perform runtime network requests or transmit user data.
Both URLs appear in documentation text only. No executable code, fetch call, webhook, or data transfer path was found.
Static false positives ignored (2)

These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.

Low
Weak Cryptography Static Matches Are False Positives
The flagged lines contain prompt-writing guidance and examples, not cryptographic APIs or hashing logic. No weak cryptographic algorithm use was found.
The reviewed lines are natural language prompt instructions. There are no imports, functions, commands, or cryptographic primitives in the skill files.
Low
Reconnaissance And Command Static Matches Are False Positives
The reconnaissance matches are generic creative workflow phrases. The command execution match is a Markdown code-formatted reference path, not shell execution.
The flagged text is documentation for creative prompt construction. The backticks at SKILL.md line 91 wrap a file path and do not invoke Ruby, shell, or any executable command.

Risk Factors

🌐 Network access (2)
Audited by: codex

Apr 9, 2026, 02:14 PM

All 15 static analysis findings are false positives. Hardcoded URLs are documentation links. Backtick patterns are markdown formatting, not shell execution. No cryptographic code, system reconnaissance, or network calls exist in the skill. The skill is a text-based creative writing assistant that generates prompts for MaxArt.ai image and video generation with no code execution capabilities.

3
Files scanned
221
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude