Audit History
react-server-components-framework - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 23, 2026, 06:34 AM | 4 confirmed | 0 | No capability change |
| v8 | Jul 7, 2026, 06:13 PM | No confirmed findings | 0 | No capability change |
| v7 | Jul 5, 2026, 03:06 AM | 1 confirmed | 62 | No capability change |
| v6 | Jun 28, 2026, 10:26 AM | 3 confirmed | 2 | Contains scripts |
| v5 | Jan 16, 2026, 05:06 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 05:06 PM | No confirmed findings | 0 | External commandsNetwork accessEnv variables |
| v3 | Jan 10, 2026, 10:50 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 10:50 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 10:50 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 06:34 AM
All 127 static alerts are false positives caused by documentation formatting, standard React patterns, placeholder fetch calls, or server-only environment access. Manual review found stored cross-site scripting, missing authorization, mass assignment, and draft disclosure in the supplied examples. These examples require security hardening before publication.
Confirmed security concerns (4)
Risk Factors
⚙️ External commands (50)
⚡ Contains scripts (1)
🌐 Network access (24)
Jul 7, 2026, 06:13 PM
The static findings were reviewed in context and appear to be false positives from documentation, templates, code fences, and placeholder examples. No prompt injection, hidden command execution, credential exfiltration, or malicious network behavior was found.
Risk Factors
⚙️ External commands (61)
⚡ Contains scripts (1)
🌐 Network access (24)
Jul 5, 2026, 03:06 AM
The static findings are false positives caused by Markdown backticks, JavaScript template literals, placeholder fetch calls, and server-only environment variable examples. No prompt injection or malicious intent was found, but the Server Action template should add consistent authorization before destructive or bulk mutations.
Confirmed security concerns (1)
Capability review items (62)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (61)
⚡ Contains scripts (1)
🌐 Network access (24)
Jun 28, 2026, 10:26 AM
Static analysis reported many command, network, environment, and browser-storage patterns, but review found these are primarily markdown and TypeScript examples for Next.js development rather than hidden executable behavior. No prompt-injection text or confirmed malicious intent was found. The skill should publish with a warning because some copyable examples need stronger security caveats, especially stored HTML rendering and authorization checks for destructive actions.
Confirmed security concerns (3)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (246)
⚡ Contains scripts (1)
🌐 Network access (24)
Jan 16, 2026, 05:06 PM
Pure documentation skill containing markdown guides and code templates for React Server Components. Static scanner findings are false positives - backticks in markdown code blocks were misinterpreted as shell execution, validation patterns as crypto algorithms, and documentation examples as network calls. No executable scripts, network calls, or concerning patterns detected.
Risk Factors
⚙️ External commands (1)
🌐 Network access (1)
🔑 Env variables (1)
Jan 16, 2026, 05:06 PM
Pure documentation skill containing markdown guides and code templates for React Server Components. Static scanner findings are false positives - backticks in markdown code blocks were misinterpreted as shell execution, validation patterns as crypto algorithms, and documentation examples as network calls. No executable scripts, network calls, or concerning patterns detected.
Risk Factors
⚙️ External commands (1)
🌐 Network access (1)
🔑 Env variables (1)
Jan 10, 2026, 10:50 AM
Pure documentation skill containing markdown guides and code templates for React Server Components. No executable scripts, network calls, or concerning patterns detected.
Jan 10, 2026, 10:50 AM
Pure documentation skill containing markdown guides and code templates for React Server Components. No executable scripts, network calls, or concerning patterns detected.
Jan 10, 2026, 10:50 AM
Pure documentation skill containing markdown guides and code templates for React Server Components. No executable scripts, network calls, or concerning patterns detected.