Skills sheet-to-report Audit History
📦

Audit History

sheet-to-report - 3 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v3 LatestSep 21, 2026, 06:59 AM 1 confirmed0No capability change
v2 Sep 16, 2026, 07:50 AM No confirmed findings0No capability change
v1 Sep 11, 2026, 12:39 PM No confirmed findings0Baseline

Sep 21, 2026, 06:59 AM

All 400 catalogued static findings were adjudicated as false positives after targeted source review. Obfuscation alerts map to readable Chinese text, generated HTML or CSS, and ordinary collection syntax; local command and filesystem operations use bounded arguments and generated directories. No prompt injection or exfiltration intent was found, but 386 scanner matches omitted by the static cap still require cataloguing before automatic publication. Static review was capped at 400/786 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.

117
Files scanned
28,897
Lines analyzed
6
Review items
0
False positives ignored

Confirmed security concerns (1)

Low
Unscanned file (too_large) — manual review required
[unscanned: too_large]
Force-confirmed metadata/low static finding; AI false-positive verdict rejected.

Risk Factors

🌐 Network access (42)
⚙️ External commands (50)
.github/workflows/public-checks.yml:53 .github/workflows/public-checks.yml:29 scripts/analysis_engine.py:592 scripts/chapter_chart_geometry.mjs:14 scripts/chapter_chart_geometry.mjs:120 scripts/chapter_deck.mjs:5 scripts/chapter_deck.mjs:14 scripts/chapter_deck.mjs:199 scripts/chapter_deck.mjs:49 scripts/chapter_deck.mjs:104 scripts/chapter_deck.mjs:173 scripts/chapter_deck.mjs:184 scripts/chapter_deck.mjs:185 scripts/chapter_deck.mjs:186 scripts/chapter_deck.mjs:188 scripts/chapter_deck.mjs:189 scripts/chapter_deck.mjs:191 scripts/chapter_deck.mjs:192 scripts/chapter_deck.mjs:193 scripts/chapter_deck.mjs:196 scripts/chapter_slideviber_design.mjs:19 scripts/chapter_slideviber_design.mjs:40 scripts/chapter_slideviber_design.mjs:56 scripts/content_qa.py:53 scripts/content_resolver.py:17 scripts/environment_check.py:47 scripts/html_analysis.py:60 scripts/ppt_theme_samples.mjs:6 scripts/ppt_theme_samples.mjs:15 scripts/ppt_theme_samples.mjs:51 scripts/ppt_theme_samples.mjs:54 scripts/ppt_theme_samples.mjs:48 scripts/ppt_theme_samples.mjs:60 scripts/ppt_theme_samples.mjs:79 scripts/report_model_projection.py:47 scripts/report_model_projection.py:189 scripts/slideviber_consistency.py:428 scripts/slideviber_consistency.py:429 scripts/slideviber_handoff.py:39 scripts/slideviber_handoff.py:44 scripts/slideviber_handoff.py:57 scripts/slideviber_handoff.py:65 scripts/slideviber_handoff.py:82 scripts/slideviber_handoff.py:93 scripts/slideviber_handoff.py:94 scripts/slideviber_handoff.py:95 scripts/slideviber_handoff.py:98 scripts/slideviber_handoff.py:113 scripts/visual_verification.py:102 scripts/visual_verification.py:128
⚡ Contains scripts (50)
📁 Filesystem access (43)
🔑 Env variables (11)
Audited by: codex

Sep 16, 2026, 07:50 AM

All 400 presented static findings are false positives caused by documentation, CJK text, generated HTML, validation helpers, or bounded local report tooling. External commands use fixed argument arrays without shell interpolation, and no prompt injection, secret collection, data exfiltration, or covert network behavior was found. Static review was capped at 400/728 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.

108
Files scanned
28,441
Lines analyzed
5
Review items
0
False positives ignored

Risk Factors

🌐 Network access (35)
⚙️ External commands (50)
.github/workflows/public-checks.yml:51 .github/workflows/public-checks.yml:27 scripts/analysis_engine.py:592 scripts/chapter_chart_geometry.mjs:14 scripts/chapter_chart_geometry.mjs:120 scripts/chapter_deck.mjs:5 scripts/chapter_deck.mjs:14 scripts/chapter_deck.mjs:199 scripts/chapter_deck.mjs:49 scripts/chapter_deck.mjs:104 scripts/chapter_deck.mjs:173 scripts/chapter_deck.mjs:184 scripts/chapter_deck.mjs:185 scripts/chapter_deck.mjs:186 scripts/chapter_deck.mjs:188 scripts/chapter_deck.mjs:189 scripts/chapter_deck.mjs:191 scripts/chapter_deck.mjs:192 scripts/chapter_deck.mjs:193 scripts/chapter_deck.mjs:196 scripts/chapter_slideviber_design.mjs:19 scripts/chapter_slideviber_design.mjs:40 scripts/chapter_slideviber_design.mjs:56 scripts/content_qa.py:53 scripts/content_resolver.py:17 scripts/environment_check.py:47 scripts/html_analysis.py:60 scripts/ppt_theme_samples.mjs:6 scripts/ppt_theme_samples.mjs:15 scripts/ppt_theme_samples.mjs:51 scripts/ppt_theme_samples.mjs:54 scripts/ppt_theme_samples.mjs:48 scripts/ppt_theme_samples.mjs:60 scripts/ppt_theme_samples.mjs:79 scripts/report_model_projection.py:47 scripts/report_model_projection.py:189 scripts/slideviber_consistency.py:428 scripts/slideviber_consistency.py:429 scripts/slideviber_handoff.py:39 scripts/slideviber_handoff.py:44 scripts/slideviber_handoff.py:57 scripts/slideviber_handoff.py:65 scripts/slideviber_handoff.py:82 scripts/slideviber_handoff.py:93 scripts/slideviber_handoff.py:94 scripts/slideviber_handoff.py:95 scripts/slideviber_handoff.py:98 scripts/slideviber_handoff.py:113 scripts/visual_verification.py:102 scripts/visual_verification.py:128
⚡ Contains scripts (50)
📁 Filesystem access (43)
🔑 Env variables (11)
Audited by: codex

Sep 11, 2026, 12:39 PM

All 400 presented static findings were reviewed and judged false positives: they describe normal local report generation, validation, rendering, documentation, or repository hygiene. No prompt injection, credential exfiltration, or malicious intent was evidenced in the reviewed locations; 318 repeated or lower-priority matches remain outside the presented catalog, and no net-new semantic finding was identified. Static review was capped at 400/718 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.

103
Files scanned
28,004
Lines analyzed
5
Review items
0
False positives ignored

Risk Factors

⚙️ External commands (50)
.github/workflows/public-checks.yml:51 .github/workflows/public-checks.yml:27 scripts/analysis_engine.py:592 scripts/chapter_chart_geometry.mjs:14 scripts/chapter_chart_geometry.mjs:120 scripts/chapter_deck.mjs:5 scripts/chapter_deck.mjs:14 scripts/chapter_deck.mjs:199 scripts/chapter_deck.mjs:49 scripts/chapter_deck.mjs:104 scripts/chapter_deck.mjs:173 scripts/chapter_deck.mjs:184 scripts/chapter_deck.mjs:185 scripts/chapter_deck.mjs:186 scripts/chapter_deck.mjs:188 scripts/chapter_deck.mjs:189 scripts/chapter_deck.mjs:191 scripts/chapter_deck.mjs:192 scripts/chapter_deck.mjs:193 scripts/chapter_deck.mjs:196 scripts/chapter_slideviber_design.mjs:19 scripts/chapter_slideviber_design.mjs:40 scripts/chapter_slideviber_design.mjs:56 scripts/content_qa.py:53 scripts/content_resolver.py:17 scripts/environment_check.py:47 scripts/html_analysis.py:60 scripts/ppt_theme_samples.mjs:6 scripts/ppt_theme_samples.mjs:15 scripts/ppt_theme_samples.mjs:51 scripts/ppt_theme_samples.mjs:54 scripts/ppt_theme_samples.mjs:48 scripts/ppt_theme_samples.mjs:60 scripts/ppt_theme_samples.mjs:79 scripts/report_model_projection.py:47 scripts/report_model_projection.py:189 scripts/slideviber_consistency.py:428 scripts/slideviber_consistency.py:429 scripts/slideviber_handoff.py:39 scripts/slideviber_handoff.py:44 scripts/slideviber_handoff.py:57 scripts/slideviber_handoff.py:65 scripts/slideviber_handoff.py:82 scripts/slideviber_handoff.py:93 scripts/slideviber_handoff.py:94 scripts/slideviber_handoff.py:95 scripts/slideviber_handoff.py:98 scripts/slideviber_handoff.py:113 scripts/visual_verification.py:102 scripts/visual_verification.py:128
🌐 Network access (26)
⚡ Contains scripts (50)
📁 Filesystem access (43)
🔑 Env variables (11)
Audited by: codex