Audit History
market-research-reports - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 5, 2026, 06:32 PM | 2 confirmed | 0 | No capability change |
| v6 | Jul 5, 2026, 06:32 PM | 2 confirmed | 0 | Contains scripts |
| v5 | Jun 30, 2026, 06:24 AM | 2 confirmed | 0 | Contains scriptsFilesystem access |
| v4 | Jan 17, 2026, 06:16 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 06:16 AM | No confirmed findings | 0 | Filesystem access |
| v2 | Jan 12, 2026, 05:05 PM | No confirmed findings | 0 | External commandsFilesystem access Contains scripts |
| v1 | Jan 4, 2026, 04:56 PM | No confirmed findings | 1 | Baseline |
Jul 5, 2026, 06:32 PM
Most static findings are false positives caused by LaTeX paths, Markdown code fences, or business research terms. The Python subprocess call uses list arguments and no shell interpolation. Separate semantic issues remain for embedded safe-audit claims and external service promotion.
Confirmed security concerns (2)
Risk Factors
📁 Filesystem access (34)
⚙️ External commands (50)
Jul 5, 2026, 06:32 PM
Most static findings are false positives caused by LaTeX paths, Markdown code fences, or business research terms. The Python subprocess call uses list arguments and no shell interpolation. Separate semantic issues remain for embedded safe-audit claims and external service promotion.
Confirmed security concerns (2)
Risk Factors
📁 Filesystem access (34)
⚙️ External commands (50)
Jun 30, 2026, 06:24 AM
Static analysis reported many critical and high patterns, but most are false positives from LaTeX syntax, Markdown examples, and market sizing terms. The confirmed concern is operational: the visual generation helper invokes local Python tools and writes to a user-supplied output directory, so publication should include a filesystem warning.
Confirmed security concerns (2)
Static false positives ignored (4)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (2)
📁 Filesystem access (2)
Detected Patterns
Jan 17, 2026, 06:16 AM
All 527 static findings are FALSE POSITIVES. The scanner misinterpreted business terminology (SAM=Serviceable Addressable Market), LaTeX commands as cryptographic algorithms, markdown code blocks as shell commands, and standard file paths as path traversal. The only subprocess.run call uses hardcoded arguments to invoke sibling skills with no injection risk.
Risk Factors
⚙️ External commands (1)
Jan 17, 2026, 06:16 AM
All 527 static findings are FALSE POSITIVES. The scanner misinterpreted business terminology (SAM=Serviceable Addressable Market), LaTeX commands as cryptographic algorithms, markdown code blocks as shell commands, and standard file paths as path traversal. The only subprocess.run call uses hardcoded arguments to invoke sibling skills with no injection risk.
Risk Factors
⚙️ External commands (1)
Jan 12, 2026, 05:05 PM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
⚙️ External commands (301)
📁 Filesystem access (33)
Detected Patterns
Jan 4, 2026, 04:56 PM
Simple script-based visual generator with no data exfiltration or persistence capabilities. Subprocess usage is limited to invoking local generator scripts.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.