Audit History
screenfull-fullscreen-api - 6 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v6 Latest | Jul 4, 2026, 05:26 PM | No confirmed findings | 0 | No capability change |
| v5 | Jul 4, 2026, 05:26 PM | No confirmed findings | 0 | No capability change |
| v4 | Jun 27, 2026, 05:17 PM | 1 confirmed | 1 | No capability change |
| v3 | Jan 16, 2026, 01:45 PM | No confirmed findings | 0 | No capability change |
| v2 | Jan 16, 2026, 01:45 PM | No confirmed findings | 0 | Network accessExternal commands |
| v1 | Jan 10, 2026, 09:37 AM | No confirmed findings | 0 | Baseline |
Jul 4, 2026, 05:26 PM
All static findings are false positives caused by Markdown code fences, screenfull API method names, keyboard event property names, and reference links. I found no prompt injection, data exfiltration intent, system reconnaissance, certificate handling, or executable malware behavior in SKILL.md.
Risk Factors
⚙️ External commands (20)
🌐 Network access (6)
Jul 4, 2026, 05:26 PM
All static findings are false positives caused by Markdown code fences, screenfull API method names, keyboard event property names, and reference links. I found no prompt injection, data exfiltration intent, system reconnaissance, certificate handling, or executable malware behavior in SKILL.md.
Risk Factors
⚙️ External commands (20)
🌐 Network access (6)
Jun 27, 2026, 05:17 PM
The static scan reported many high and critical patterns, but most are false positives caused by Markdown code fences, fullscreen API names, keyboard examples, and documentation URLs. No prompt injection, credential access, obfuscation, or malicious exfiltration evidence was found in SKILL.md. The main confirmed concern is an Angular [innerHTML] example that could encourage unsafe rendering if adapted to user-controlled content.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (1)
🌐 Network access (2)
Detected Patterns
Jan 16, 2026, 01:45 PM
Documentation-only skill containing instructional markdown with code examples for using the screenfull library. No executable code, no network calls, no file system access, no environment variable reading. Purely a reference guide for implementing browser fullscreen API functionality.
Risk Factors
🌐 Network access (6)
⚙️ External commands (20)
Jan 16, 2026, 01:45 PM
Documentation-only skill containing instructional markdown with code examples for using the screenfull library. No executable code, no network calls, no file system access, no environment variable reading. Purely a reference guide for implementing browser fullscreen API functionality.
Risk Factors
🌐 Network access (6)
⚙️ External commands (20)
Jan 10, 2026, 09:37 AM
Documentation-only skill containing instructional markdown with code examples for using the screenfull library. No executable code, no network calls, no file system access, no environment variable reading. Purely a reference guide for implementing browser fullscreen API functionality.