Skills typeset Audit History
📦

Audit History

typeset - 4 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v4 LatestJul 6, 2026, 08:49 PM No confirmed findings0No capability change
v3 Jul 6, 2026, 08:49 PM No confirmed findings0External commands
v2 Jun 30, 2026, 10:46 AM No confirmed findings0No capability change
v1 Mar 24, 2026, 08:23 AM No confirmed findings0Baseline

Jul 6, 2026, 08:49 PM

All static findings are false positives caused by Markdown inline code around CSS and typography terms. No executable commands, system reconnaissance, prompt injection, network access, or data exfiltration intent were found in SKILL.md.

1
Files scanned
115
Lines analyzed
1
Review items
0
False positives ignored
Audited by: codex

Jul 6, 2026, 08:49 PM

All static findings are false positives caused by Markdown inline code around CSS and typography terms. No executable commands, system reconnaissance, prompt injection, network access, or data exfiltration intent were found in SKILL.md.

1
Files scanned
115
Lines analyzed
1
Review items
0
False positives ignored
Audited by: codex

Jun 30, 2026, 10:46 AM

Static analysis reported external command, weak cryptography, and reconnaissance patterns in SKILL.md. Manual review found markdown prose and inline CSS examples, with no executable code, network access, credential handling, or prompt injection attempt.

1
Files scanned
115
Lines analyzed
0
Review items
3
False positives ignored
Static false positives ignored (3)

These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.

Low
False positive: inline markdown code markers
The external command findings are markdown backticks around CSS terms and design examples. They do not execute shell, Ruby, or other commands.
The referenced lines contain prose and inline CSS terms only. No command runner, script block, subprocess call, or user input execution path is present.
Low
False positive: weak cryptography patterns in prose
The weak cryptography findings are on descriptive text and a markdown reference. No hashing, encryption, or cryptographic API usage appears on these lines.
The cited lines discuss typography guidance and skill references. I found no evidence of MD5, SHA-1, insecure random generation, or credential processing.
Low
False positive: system reconnaissance patterns in CSS guidance
The reconnaissance findings are CSS sizing guidance for rem units and clamp usage. They do not inspect the host, environment, files, users, or network.
The referenced lines are typography layout recommendations. No filesystem discovery, OS probing, environment inspection, or network enumeration is present.
No confirmed security findings were recorded for this completed audit.
Audited by: codex

Mar 24, 2026, 08:23 AM

All 26 static analysis findings are false positives. The scanner misinterpreted CSS code snippets (e.g., font-display, max-width, tabular-nums) as shell commands and typography analysis instructions as system reconnaissance. This is a design guideline document with no executable code, network access, filesystem operations, or cryptographic functions. Safe for publication.

1
Files scanned
115
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude