Audit History
browser-testing-with-devtools - 2 audits
Version comparison
Capability and finding changes across audited versions, newest first.
Sep 19, 2026, 11:30 AM
All 30 static findings are false positives in the audited documentation. The command, filesystem, network, screenshot, reconnaissance, and prompt-injection matches describe configuration, safe testing boundaries, or local verification steps rather than malicious behavior.
Risk Factors
⚙️ External commands (22)
🌐 Network access (2)
📁 Filesystem access (2)
Sep 13, 2026, 01:03 PM
Most static alerts are false positives caused by Markdown backticks, local test examples, and explicit security safeguards. The installation example presents a real supply-chain risk because it uses npx with automatic confirmation and an unpinned latest package.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.