Audit History
design-system-starter - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 23, 2026, 06:03 AM | No confirmed findings | 0 | No capability change |
| v8 | Jul 8, 2026, 12:06 AM | No confirmed findings | 0 | No capability change |
| v7 | Jul 6, 2026, 04:14 AM | No confirmed findings | 0 | External commandsFilesystem accessNetwork access |
| v6 | Jun 28, 2026, 09:47 AM | No confirmed findings | 0 | External commandsFilesystem accessNetwork access |
| v5 | Jan 16, 2026, 04:30 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 04:30 PM | No confirmed findings | 0 | External commandsFilesystem accessNetwork access |
| v3 | Jan 10, 2026, 10:33 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 10:33 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 10:33 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 06:03 AM
All 63 static findings are false positives caused by documentation syntax, relative imports, keyboard-event properties, public links, schema metadata, or design-system language. The reviewed files contain no command execution, path traversal, secret handling, unauthorized networking, prompt injection, or malicious intent.
Risk Factors
⚙️ External commands (50)
📁 Filesystem access (2)
🌐 Network access (2)
Jul 8, 2026, 12:06 AM
The static alerts are false positives caused by Markdown formatting, React template literals, relative imports, keyboard event checks, and documentation links. I found no evidence of shell execution, path traversal, credential handling, system reconnaissance, prompt injection, or malicious network activity.
Risk Factors
⚙️ External commands (51)
📁 Filesystem access (2)
🌐 Network access (2)
Jul 6, 2026, 04:14 AM
I reviewed all 63 static findings and found false positives from markdown fences, inline code, TypeScript examples, schema links, and accessibility text. No evidence of command execution, credential handling, malicious networking, filesystem abuse, or prompt injection was found.
Risk Factors
⚙️ External commands (51)
📁 Filesystem access (2)
🌐 Network access (2)
Jun 28, 2026, 09:47 AM
Static analysis reported many high-risk patterns, but context review found documentation examples, Markdown code fences, relative imports, design token color values, and public reference URLs. No malicious intent, credential access, command execution, data exfiltration, or prompt injection evidence was found. The only notable behavior is a benign example that stores a theme preference in localStorage.
Static false positives ignored (5)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Jan 16, 2026, 04:30 PM
This is a pure documentation skill containing design system guidance, JSON token schemas, TypeScript component templates, and accessibility checklists. The static analyzer generated false positives by misinterpreting markdown code fences as shell backticks, JSON keys as cryptographic algorithms, and documentation patterns as reconnaissance. All findings are dismissed as false positives.
Risk Factors
⚙️ External commands (71)
📁 Filesystem access (2)
🌐 Network access (2)
Jan 16, 2026, 04:30 PM
This is a pure documentation skill containing design system guidance, JSON token schemas, TypeScript component templates, and accessibility checklists. The static analyzer generated false positives by misinterpreting markdown code fences as shell backticks, JSON keys as cryptographic algorithms, and documentation patterns as reconnaissance. All findings are dismissed as false positives.
Risk Factors
⚙️ External commands (71)
📁 Filesystem access (2)
🌐 Network access (2)
Jan 10, 2026, 10:33 AM
This is a pure documentation and template skill with no executable code, network calls, or file system access. It contains only design system guidance, JSON token schemas, TypeScript component templates, and accessibility checklists.
Jan 10, 2026, 10:33 AM
This is a pure documentation and template skill with no executable code, network calls, or file system access. It contains only design system guidance, JSON token schemas, TypeScript component templates, and accessibility checklists.
Jan 10, 2026, 10:33 AM
This is a pure documentation and template skill with no executable code, network calls, or file system access. It contains only design system guidance, JSON token schemas, TypeScript component templates, and accessibility checklists.