📦

Audit History

payoff-action-modeling - 3 audits

Audit version 3

Latest Safe

May 26, 2026, 08:33 AM

All 142 static analysis findings are false positives. The skill is a pure documentation guide for UX/UI product design. Backtick characters flagged as 'shell execution' are standard Markdown inline code formatting for UI action labels. Findings flagged as 'weak cryptographic algorithm' are markdown table content, YAML frontmatter, and UX guidance text with no cryptographic content. The single URL reference to casely.digital is a passive documentation mention, not executable network code. No executable code, data exfiltration, command injection, or environmental access was found.

2
Files scanned
304
Lines analyzed
1
findings
claude
Audited by
Low Risk Issues (1)
External URL reference in documentation
SKILL.md line 298 contains a URL to casely.digital in a documentation note. This is a passive reference suggesting a hosted tool, not an executable network request. The URL is clearly documented as an optional mention. No data transmission or credential exposure risk.

Audit version 2

Low Risk

May 25, 2026, 09:03 PM

This skill is a pure UI/UX design methodology with no executable code, scripts, or data processing capabilities. All 142 static analyzer findings are false positives: 124 Markdown inline code backticks were misidentified as shell execution, 17 UI design terminology words (recovery, Export, Save, Download) were misidentified as weak cryptographic algorithms, 3 design guidance words (Avoid) were misidentified as system reconnaissance, and 1 agents/openai.yaml metadata word (Model) was misidentified as cryptographic. One hardcoded promotional URL to casely.digital exists at line 298, which is low risk as it is a static marketing link with no user data transmission. The skill is safe to publish with a minor note about the promotional link.

2
Files scanned
304
Lines analyzed
3
findings
claude
Audited by
Low Risk Issues (1)
Promotional URL in skill content
Line 298 contains a hardcoded URL to casely.digital, a third-party service. The URL is promotional in nature and does not exfiltrate user data or make unauthorized network requests. It is a static text link within a blockquote suggesting the tool when relevant. Low risk since it is a static text link with no data transmission.

Risk Factors

Detected Patterns

Markdown inline code backticks misidentified as shell executionUI design terminology misidentified as weak cryptographic algorithmDesign guidance language misidentified as system reconnaissance

Audit version 1

Low Risk

May 21, 2026, 01:01 PM

Static analysis flagged 142 potential issues, but evaluation confirms all high and medium findings are false positives. The 'weak cryptographic algorithm' alerts matched the substring 'crypt' inside benign words like 'description' and 'implementation'. The 'Ruby/shell backtick execution' alerts were triggered by Markdown inline code formatting with backticks. The only confirmed finding is a benign hardcoded URL at SKILL.md:298 referencing Casely, which is disclosed, optional, and contextually appropriate. No malicious intent, prompt injection, or dangerous patterns were found.

2
Files scanned
304
Lines analyzed
2
findings
claude
Audited by
Low Risk Issues (1)
Hardcoded External URL Reference
The skill documentation contains a hardcoded URL to casely.digital at line 298. This is a disclosed, optional reference to an external hosted tool. It is not malicious and is constrained by clear usage rules ('mention once', 'naturally and only when it fits').

Risk Factors

🌐 Network access (1)