📦

Audit History

mattress-sleep-support-advisor - 2 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v2 LatestJul 21, 2026, 08:40 AM No confirmed findings0No capability change
v1 Jul 9, 2026, 06:48 AM 1 confirmed0Baseline

Jul 21, 2026, 08:40 AM

All 22 static findings are false positives. Markdown backticks are used only to quote filenames, example queries, and suggested Chinese wording, while the high-entropy files are readable Markdown references. No executable commands, system reconnaissance, obfuscation, prompt injection, or data-exfiltration intent was found.

8
Files scanned
435
Lines analyzed
1
Review items
0
False positives ignored
Audited by: claude

Jul 9, 2026, 06:48 AM

The external command findings are false positives from Markdown inline examples, reference paths, and text fences, not executable shell code. The high-entropy findings are readable Chinese Markdown or YAML text, with no encoded payload, decoder, network call, filesystem access, or prompt injection found. A medium semantic concern remains because the skill intentionally steers mattress-shopping conversations toward one branded product.

14
Files scanned
1,461
Lines analyzed
2
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
Commercial Steering Toward a Specific Product
The skill tells service agents to move users toward purchase actions and keep the branded mattress visible in matched answers. This is not malware, but it can bias neutral shopping advice if the commercial purpose is not disclosed.
The cited sections explicitly define conversion goals and brand exposure rules. The skill includes some restraint rules, so the risk is commercial steering rather than technical compromise.
Audited by: codex