Audit History
nextjs-app-router-patterns - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | 4 авг. 2026 г., 15:53 | 1 confirmed | 0 | No capability change |
| v4 | 7 июл. 2026 г., 01:10 | 1 confirmed | 0 | No capability change |
| v3 | 7 июл. 2026 г., 01:10 | 1 confirmed | 0 | External commands |
| v2 | 30 июн. 2026 г., 16:35 | 2 confirmed | 0 | External commands |
| v1 | 24 февр. 2026 г., 16:13 | No confirmed findings | 0 | Baseline |
4 авг. 2026 г., 15:53
All 22 static findings are false positives caused by JavaScript template literals, Markdown code references, and ordinary Next.js examples. However, the playbook demonstrates database mutations without explicit schema validation or authorization, creating a high-risk pattern when copied into production.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (4)
🌐 Network access (7)
🔑 Env variables (2)
7 июл. 2026 г., 01:10
The static command, network, environment, sensitive-file, and reconnaissance alerts are false positives in Markdown and TypeScript documentation samples. No prompt injection or malware intent was found. Semantic review found that mutation examples should add validation and authorization guidance before publication.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (4)
🌐 Network access (7)
🔑 Env variables (2)
7 июл. 2026 г., 01:10
The static command, network, environment, sensitive-file, and reconnaissance alerts are false positives in Markdown and TypeScript documentation samples. No prompt injection or malware intent was found. Semantic review found that mutation examples should add validation and authorization guidance before publication.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (4)
🌐 Network access (7)
🔑 Env variables (2)
30 июн. 2026 г., 16:35
Static analysis reported command execution, weak cryptography, reconnaissance, network, and environment access patterns. Review found the command, weak-crypto, and reconnaissance alerts are false positives caused by Markdown code fences, file names, comments, and normal Next.js examples. The skill is safe to publish with low risk because it contains documentation only, but some copyable examples need validation and authorization hardening.
Confirmed security concerns (2)
Risk Factors
24 февр. 2026 г., 16:13
This skill contains documentation-only markdown files with Next.js educational code examples. All 56 static findings are false positives because the scanner incorrectly flagged markdown code blocks as executable code. No actual security risks detected.