Audit History
viral-short-form - 4 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v4 Latest | Jul 7, 2026, 07:26 AM | No confirmed findings | 0 | No capability change |
| v3 | Jul 7, 2026, 07:26 AM | No confirmed findings | 0 | Filesystem accessExternal commandsNetwork access |
| v2 | Jun 30, 2026, 11:08 PM | No confirmed findings | 0 | External commandsNetwork accessFilesystem access |
| v1 | Jun 26, 2026, 09:16 AM | No confirmed findings | 0 | Baseline |
Jul 7, 2026, 07:26 AM
I found no evidence of code execution, filesystem access, data exfiltration, or prompt injection. The static alerts are Markdown links, inline-code references, or ordinary content guidance in the README, SKILL, assets, and reference files. The only external URL is documentation media and linking, not agent-initiated network behavior.
Risk Factors
📁 Filesystem access (2)
⚙️ External commands (25)
🌐 Network access (1)
Jul 7, 2026, 07:26 AM
I found no evidence of code execution, filesystem access, data exfiltration, or prompt injection. The static alerts are Markdown links, inline-code references, or ordinary content guidance in the README, SKILL, assets, and reference files. The only external URL is documentation media and linking, not agent-initiated network behavior.
Risk Factors
📁 Filesystem access (2)
⚙️ External commands (25)
🌐 Network access (1)
Jun 30, 2026, 11:08 PM
Static analysis reported 73 potential issues across Markdown files, but review found no executable code, shell invocation, cryptographic implementation, system reconnaissance, prompt injection, or data exfiltration. The flagged items are Markdown code fences, backticked file names, relative documentation links, ordinary URLs, and prose about content strategy. The skill is safe to publish as instructional writing content.
Static false positives ignored (5)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Jun 26, 2026, 09:16 AM
Static analyzer flagged 73 potential patterns (external_commands, filesystem traversal, weak crypto, hardcoded URLs, system recon). After full review of all 10 files (701 lines), every finding is a false positive: the skill contains only markdown documentation about short-form video content creation. Backticks are markdown formatting, not shell execution. Path traversal patterns are relative link references in markdown. Weak crypto and system recon flags are keyword matches in prose (e.g. 'weak hook', 'system reconnaissance' phrases). No executable code, no scripts, no network calls exist in the skill. The skill is pure instructional content for content creators with no security risk.