Audit History
Code Patterns & Practices - 12 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v12 Latest | Jul 18, 2026, 10:14 AM | No confirmed findings | 0 | No capability change |
| v11 | Jul 17, 2026, 10:26 AM | No confirmed findings | 0 | No capability change |
| v10 | Jul 17, 2026, 10:26 AM | No confirmed findings | 0 | No capability change |
| v9 | Jul 17, 2026, 10:26 AM | No confirmed findings | 0 | No capability change |
| v8 | Jul 6, 2026, 02:46 AM | No confirmed findings | 0 | No capability change |
| v7 | Jul 6, 2026, 02:46 AM | No confirmed findings | 0 | No capability change |
| v6 | Jun 28, 2026, 12:58 PM | No confirmed findings | 0 | No capability change |
| v5 | Jan 16, 2026, 07:30 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 07:30 PM | No confirmed findings | 0 | Network accessContains scriptsExternal commands |
| v3 | Jan 10, 2026, 10:55 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 10:55 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 10:55 AM | No confirmed findings | 0 | Baseline |
Jul 18, 2026, 10:14 AM
All 31 static findings are false positives caused by Markdown fences, TypeScript template literals, an illustrative relative API request, public documentation links, and a section heading. The skill is documentation-only and contains no prompt injection, command execution, credential access, or data-exfiltration intent.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (26)
🌐 Network access (3)
Jul 17, 2026, 10:26 AM
All 31 static detections are false positives caused by Markdown code fences, educational React Native examples, and documentation links. The skill contains no executable shell commands, dynamic untrusted code loading, credential handling, or evidence of prompt injection. No semantic security concerns were identified.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (26)
🌐 Network access (3)
Jul 17, 2026, 10:26 AM
All 31 static detections are false positives caused by Markdown code fences, educational React Native examples, and documentation links. The skill contains no executable shell commands, dynamic untrusted code loading, credential handling, or evidence of prompt injection. No semantic security concerns were identified.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (26)
🌐 Network access (3)
Jul 17, 2026, 10:26 AM
All 31 static detections are false positives caused by Markdown code fences, educational React Native examples, and documentation links. The skill contains no executable shell commands, dynamic untrusted code loading, credential handling, or evidence of prompt injection. No semantic security concerns were identified.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (26)
🌐 Network access (3)
Jul 6, 2026, 02:46 AM
All static findings were adjudicated as false positives in a Markdown documentation skill. The flagged patterns are TypeScript examples, Markdown code fences, a relative fetch example, and resource links; no prompt injection, data exfiltration intent, or executable automation was found.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (26)
🌐 Network access (3)
Jul 6, 2026, 02:46 AM
All static findings were adjudicated as false positives in a Markdown documentation skill. The flagged patterns are TypeScript examples, Markdown code fences, a relative fetch example, and resource links; no prompt injection, data exfiltration intent, or executable automation was found.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (26)
🌐 Network access (3)
Jun 28, 2026, 12:58 PM
Static analysis found command execution, script, network, weak crypto, and reconnaissance patterns, but review shows they are false positives in Markdown documentation and React Native examples. The skill allows only Read, Write, and Edit tools and contains no prompt injection, executable helper scripts, credential access, or data exfiltration logic. It is safe to publish with low residual risk from benign code examples that mention fetch and dynamic imports.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (26)
🌐 Network access (3)
Jan 16, 2026, 07:30 PM
Pure documentation skill containing React Native coding patterns. All static findings are false positives caused by the scanner misinterpreting code examples and documentation syntax as security issues. The skill has minimal tool permissions (Read, Write, Edit), contains no executable code, and poses no security risk.
Risk Factors
🌐 Network access (3)
⚡ Contains scripts (1)
⚙️ External commands (26)
Jan 16, 2026, 07:30 PM
Pure documentation skill containing React Native coding patterns. All static findings are false positives caused by the scanner misinterpreting code examples and documentation syntax as security issues. The skill has minimal tool permissions (Read, Write, Edit), contains no executable code, and poses no security risk.
Risk Factors
🌐 Network access (3)
⚡ Contains scripts (1)
⚙️ External commands (26)
Jan 10, 2026, 10:55 AM
Pure documentation skill containing React Native coding patterns and best practices. Uses minimal tool permissions (Read, Write, Edit) appropriate for code guidance. No network access, no scripts, no code execution, no suspicious capabilities.
Jan 10, 2026, 10:55 AM
Pure documentation skill containing React Native coding patterns and best practices. Uses minimal tool permissions (Read, Write, Edit) appropriate for code guidance. No network access, no scripts, no code execution, no suspicious capabilities.
Jan 10, 2026, 10:55 AM
Pure documentation skill containing React Native coding patterns and best practices. Uses minimal tool permissions (Read, Write, Edit) appropriate for code guidance. No network access, no scripts, no code execution, no suspicious capabilities.