📦

Audit History

use-form-5500-mcp - 2 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v2 LatestJul 12, 2026, 03:11 AM No confirmed findings1No capability change
v1 Jul 12, 2026, 03:11 AM No confirmed findings1Baseline

Jul 12, 2026, 03:11 AM

Nine command-execution alerts are false positives caused by Markdown fences and inline code labels. The remote MCP endpoint is a confirmed low-severity network dependency, while the account-tier text is not network reconnaissance. No prompt injection or malicious intent was found.

1
Files scanned
57
Lines analyzed
3
Review items
0
False positives ignored
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Low
Hardcoded URL
https://swhejpcukgzywbwacfdv.supabase.co/functions/v1/mcp
Line 15 supplies a fixed external Supabase endpoint for authenticated MCP requests. This is intentional functionality, but it creates a real network and third-party trust dependency.
Audited by: codex

Jul 12, 2026, 03:11 AM

Nine command-execution alerts are false positives caused by Markdown fences and inline code labels. The remote MCP endpoint is a confirmed low-severity network dependency, while the account-tier text is not network reconnaissance. No prompt injection or malicious intent was found.

1
Files scanned
57
Lines analyzed
3
Review items
0
False positives ignored
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Low
Hardcoded URL
https://swhejpcukgzywbwacfdv.supabase.co/functions/v1/mcp
Line 15 supplies a fixed external Supabase endpoint for authenticated MCP requests. This is intentional functionality, but it creates a real network and third-party trust dependency.
Audited by: codex