Audit History
imagegen-frontend-web - 4 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v4 Latest | Jul 6, 2026, 06:11 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 6, 2026, 06:11 PM | No confirmed findings | 0 | External commands |
| v2 | Jun 30, 2026, 08:04 AM | No confirmed findings | 0 | No capability change |
| v1 | May 20, 2026, 09:19 AM | No confirmed findings | 0 | Baseline |
Jul 6, 2026, 06:11 PM
All static findings were adjudicated as false positives. The external command alerts are Markdown inline-code descriptions, and the reconnaissance alerts are design vocabulary in SKILL.md. No evidence found of command execution, network probing, system reconnaissance, prompt injection, or malicious intent.
Risk Factors
⚙️ External commands (8)
Jul 6, 2026, 06:11 PM
All static findings were adjudicated as false positives. The external command alerts are Markdown inline-code descriptions, and the reconnaissance alerts are design vocabulary in SKILL.md. No evidence found of command execution, network probing, system reconnaissance, prompt injection, or malicious intent.
Risk Factors
⚙️ External commands (8)
Jun 30, 2026, 08:04 AM
The static backtick findings at SKILL.md lines 81-95 are Markdown inline text for design scale explanations, not shell or Ruby execution. The weak cryptography and reconnaissance alerts correspond to natural-language design guidance and example prompts in SKILL.md, with no executable code, network calls, credential handling, or prompt-injection attempt found.
May 20, 2026, 09:19 AM
The static analyzer flagged 95 pattern-based findings, but all are false positives. The SKILL.md file contains only markdown design instructions with no executable code, network calls, file system access, or cryptographic operations. The backtick characters flagged as shell execution are markdown formatting for numeric ranges. Terms like system, grid, and scan appear exclusively in frontend design contexts (design system, layout grid, visual scan order). No malicious intent detected.