📦

Audit History

browser-testing-with-devtools - 2 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v2 LatestSep 19, 2026, 11:30 AM No confirmed findings0No capability change
v1 Sep 13, 2026, 01:03 PM No confirmed findings1Baseline

Sep 19, 2026, 11:30 AM

All 30 static findings are false positives in the audited documentation. The command, filesystem, network, screenshot, reconnaissance, and prompt-injection matches describe configuration, safe testing boundaries, or local verification steps rather than malicious behavior.

1
Files scanned
318
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex

Sep 13, 2026, 01:03 PM

Most static alerts are false positives caused by Markdown backticks, local test examples, and explicit security safeguards. The installation example presents a real supply-chain risk because it uses npx with automatic confirmation and an unpinned latest package.

1
Files scanned
318
Lines analyzed
4
Review items
0
False positives ignored
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Medium
Ruby/shell backtick execution
```json
The configuration runs npx with -y and chrome-devtools-mcp@latest. This executes an unpinned network package without an installation confirmation.
Audited by: codex