📦

Audit History

Code Patterns & Practices - 12 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v12 LatestJul 18, 2026, 10:14 AM No confirmed findings0No capability change
v11 Jul 17, 2026, 10:26 AM No confirmed findings0No capability change
v10 Jul 17, 2026, 10:26 AM No confirmed findings0No capability change
v9 Jul 17, 2026, 10:26 AM No confirmed findings0No capability change
v8 Jul 6, 2026, 02:46 AM No confirmed findings0No capability change
v7 Jul 6, 2026, 02:46 AM No confirmed findings0No capability change
v6 Jun 28, 2026, 12:58 PM No confirmed findings0No capability change
v5 Jan 16, 2026, 07:30 PM No confirmed findings0No capability change
v4 Jan 16, 2026, 07:30 PM No confirmed findings0Network accessContains scriptsExternal commands
v3 Jan 10, 2026, 10:55 AM No confirmed findings0No capability change
v2 Jan 10, 2026, 10:55 AM No confirmed findings0No capability change
v1 Jan 10, 2026, 10:55 AM No confirmed findings0Baseline

Jul 18, 2026, 10:14 AM

All 31 static findings are false positives caused by Markdown fences, TypeScript template literals, an illustrative relative API request, public documentation links, and a section heading. The skill is documentation-only and contains no prompt injection, command execution, credential access, or data-exfiltration intent.

1
Files scanned
337
Lines analyzed
3
Review items
0
False positives ignored
Audited by: claude

Jul 17, 2026, 10:26 AM

All 31 static detections are false positives caused by Markdown code fences, educational React Native examples, and documentation links. The skill contains no executable shell commands, dynamic untrusted code loading, credential handling, or evidence of prompt injection. No semantic security concerns were identified.

1
Files scanned
337
Lines analyzed
3
Review items
0
False positives ignored
Audited by: claude

Jul 17, 2026, 10:26 AM

All 31 static detections are false positives caused by Markdown code fences, educational React Native examples, and documentation links. The skill contains no executable shell commands, dynamic untrusted code loading, credential handling, or evidence of prompt injection. No semantic security concerns were identified.

1
Files scanned
337
Lines analyzed
3
Review items
0
False positives ignored
Audited by: claude

Jul 17, 2026, 10:26 AM

All 31 static detections are false positives caused by Markdown code fences, educational React Native examples, and documentation links. The skill contains no executable shell commands, dynamic untrusted code loading, credential handling, or evidence of prompt injection. No semantic security concerns were identified.

1
Files scanned
337
Lines analyzed
3
Review items
0
False positives ignored
Audited by: claude

Jul 6, 2026, 02:46 AM

All static findings were adjudicated as false positives in a Markdown documentation skill. The flagged patterns are TypeScript examples, Markdown code fences, a relative fetch example, and resource links; no prompt injection, data exfiltration intent, or executable automation was found.

1
Files scanned
337
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex

Jul 6, 2026, 02:46 AM

All static findings were adjudicated as false positives in a Markdown documentation skill. The flagged patterns are TypeScript examples, Markdown code fences, a relative fetch example, and resource links; no prompt injection, data exfiltration intent, or executable automation was found.

1
Files scanned
337
Lines analyzed
3
Review items
0
False positives ignored
Audited by: codex

Jun 28, 2026, 12:58 PM

Static analysis found command execution, script, network, weak crypto, and reconnaissance patterns, but review shows they are false positives in Markdown documentation and React Native examples. The skill allows only Read, Write, and Edit tools and contains no prompt injection, executable helper scripts, credential access, or data exfiltration logic. It is safe to publish with low residual risk from benign code examples that mention fetch and dynamic imports.

1
Files scanned
337
Lines analyzed
3
Review items
3
False positives ignored
Static false positives ignored (3)

These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.

Low
Markdown Code Fences Misclassified as Shell Execution
Static alerts for Ruby or shell backtick execution correspond to Markdown TypeScript code fence delimiters and example snippets. No executable shell command, subprocess call, or user input command path is present.
The suspicious tokens are Markdown code fence delimiters around React Native and TypeScript examples. The skill metadata permits only Read, Write, and Edit tools, so these examples are not directly executed by the skill.
Low
Benign React Examples Misclassified as Script or Network Behavior
The dynamic import and fetch call are illustrative React patterns inside Markdown. The fetch target is a relative application API path, and the import target is a local component name.
Both patterns are located inside documentation examples and do not include credential access, external destinations, or obfuscation. They demonstrate normal React Native data fetching and lazy loading.
Low
Resource Links and Headings Misclassified as Dangerous Patterns
The weak crypto and reconnaissance alerts are false positives from descriptive text and headings. The hardcoded URLs are public documentation resources, not outbound exfiltration endpoints.
The cited lines contain skill description text, an anti-patterns heading, and resource links to React documentation sites. No cryptographic operation, system command, or suspicious remote collection behavior appears there.
Audited by: codex

Jan 16, 2026, 07:30 PM

Pure documentation skill containing React Native coding patterns. All static findings are false positives caused by the scanner misinterpreting code examples and documentation syntax as security issues. The skill has minimal tool permissions (Read, Write, Edit), contains no executable code, and poses no security risk.

2
Files scanned
515
Lines analyzed
3
Review items
0
False positives ignored
Audited by: claude

Jan 16, 2026, 07:30 PM

Pure documentation skill containing React Native coding patterns. All static findings are false positives caused by the scanner misinterpreting code examples and documentation syntax as security issues. The skill has minimal tool permissions (Read, Write, Edit), contains no executable code, and poses no security risk.

2
Files scanned
515
Lines analyzed
3
Review items
0
False positives ignored
Audited by: claude

Jan 10, 2026, 10:55 AM

Pure documentation skill containing React Native coding patterns and best practices. Uses minimal tool permissions (Read, Write, Edit) appropriate for code guidance. No network access, no scripts, no code execution, no suspicious capabilities.

1
Files scanned
337
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 10, 2026, 10:55 AM

Pure documentation skill containing React Native coding patterns and best practices. Uses minimal tool permissions (Read, Write, Edit) appropriate for code guidance. No network access, no scripts, no code execution, no suspicious capabilities.

1
Files scanned
337
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 10, 2026, 10:55 AM

Pure documentation skill containing React Native coding patterns and best practices. Uses minimal tool permissions (Read, Write, Edit) appropriate for code guidance. No network access, no scripts, no code execution, no suspicious capabilities.

1
Files scanned
337
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude