Skills Mobile Testing Audit History
📦

Audit History

Mobile Testing - 12 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v12 LatestJul 18, 2026, 10:16 AM No confirmed findings0No capability change
v11 Jul 17, 2026, 10:29 AM No confirmed findings0No capability change
v10 Jul 17, 2026, 10:29 AM No confirmed findings0No capability change
v9 Jul 17, 2026, 10:29 AM No confirmed findings0No capability change
v8 Jul 5, 2026, 04:59 AM No confirmed findings0No capability change
v7 Jul 5, 2026, 04:59 AM No confirmed findings0No capability change
v6 Jun 28, 2026, 01:05 PM No confirmed findings2No capability change
v5 Jan 16, 2026, 05:06 PM No confirmed findings0No capability change
v4 Jan 16, 2026, 05:06 PM No confirmed findings0Network accessExternal commands
v3 Jan 10, 2026, 10:57 AM No confirmed findings0No capability change
v2 Jan 10, 2026, 10:57 AM No confirmed findings0No capability change
v1 Jan 10, 2026, 10:57 AM No confirmed findings0Baseline

Jul 18, 2026, 10:16 AM

All 30 static findings are false positives. The external-command detections match Markdown formatting and local test commands, while the URLs are documentation links. No prompt injection, data exfiltration, or unsafe execution intent was found in SKILL.md.

1
Files scanned
195
Lines analyzed
2
Review items
0
False positives ignored
Audited by: claude

Jul 17, 2026, 10:29 AM

All 30 static findings are false positives. The external-command detections match Markdown fences and inline code in a testing guide, while the URLs are documentation references. No prompt injection, data-exfiltration intent, or executable malicious behavior was found.

1
Files scanned
195
Lines analyzed
2
Review items
0
False positives ignored
Audited by: claude

Jul 17, 2026, 10:29 AM

All 30 static findings are false positives. The external-command detections match Markdown fences and inline code in a testing guide, while the URLs are documentation references. No prompt injection, data-exfiltration intent, or executable malicious behavior was found.

1
Files scanned
195
Lines analyzed
2
Review items
0
False positives ignored
Audited by: claude

Jul 17, 2026, 10:29 AM

All 30 static findings are false positives. The external-command detections match Markdown fences and inline code in a testing guide, while the URLs are documentation references. No prompt injection, data-exfiltration intent, or executable malicious behavior was found.

1
Files scanned
195
Lines analyzed
2
Review items
0
False positives ignored
Audited by: claude

Jul 5, 2026, 04:59 AM

The detected external command patterns are markdown fences, inline formatting, and Jest examples, not executable Ruby backtick calls. The two hardcoded URLs are documentation links, and the blocker detections are normal invalid-input test examples; no semantic prompt injection or malicious intent was found.

1
Files scanned
195
Lines analyzed
2
Review items
0
False positives ignored
Audited by: codex

Jul 5, 2026, 04:59 AM

The detected external command patterns are markdown fences, inline formatting, and Jest examples, not executable Ruby backtick calls. The two hardcoded URLs are documentation links, and the blocker detections are normal invalid-input test examples; no semantic prompt injection or malicious intent was found.

1
Files scanned
195
Lines analyzed
2
Review items
0
False positives ignored
Audited by: codex

Jun 28, 2026, 01:05 PM

The static command findings are mostly fenced documentation examples for npm, Jest, and React Native Testing Library. No prompt injection, credential access, data exfiltration, or malicious intent was found in SKILL.md, but users should review project package scripts before running npm commands.

1
Files scanned
195
Lines analyzed
4
Review items
2
False positives ignored
Capability review items (2)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Medium
Bash Test Commands Require User Review
SKILL.md includes Bash examples for installing test dependencies and running npm test scripts. This is appropriate for a mobile testing skill, but npm scripts can execute project-defined commands, so users should inspect package.json before running them.
The commands are visible in fenced Bash documentation and match the stated testing purpose. Residual risk remains because npm install and npm test can invoke package lifecycle or project scripts.
Low
Documentation Links Are Static URLs
SKILL.md links to official Jest and React Native Testing Library documentation. These URLs are not evidence of data exfiltration or unauthorized network activity.
The detected URLs are ordinary documentation links at the end of the guide. They do not collect data, embed tracking code, or instruct outbound requests with secrets.
Static false positives ignored (2)

These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.

Low
Weak Cryptography Static Hits Dismissed
The reported weak cryptography locations are React Native testing examples and metadata text. No hashing, encryption, cipher selection, or credential handling code was found at these locations.
Manual review of the cited lines shows descriptions and Jest describe blocks, not cryptographic operations. The static matches are false positives.
Low
System Reconnaissance Static Hits Dismissed
The reported reconnaissance locations are test examples for invalid input handling and rendered text assertions. No host inspection, environment enumeration, or system discovery commands were found.
The cited lines are normal Jest assertions in sample tests. They do not reference operating system data, network configuration, users, files, or environment variables.

Risk Factors

⚙️ External commands (2)
🌐 Network access (2)

Detected Patterns

External Command Examples
Audited by: codex

Jan 16, 2026, 05:06 PM

Pure documentation skill containing only markdown templates and guidance for React Native testing. No executable code, network operations, or file system operations beyond reading its own content. Static findings are false positives from the scanner misinterpreting documentation code blocks and metadata as executable security risks.

2
Files scanned
376
Lines analyzed
2
Review items
0
False positives ignored
Audited by: claude

Jan 16, 2026, 05:06 PM

Pure documentation skill containing only markdown templates and guidance for React Native testing. No executable code, network operations, or file system operations beyond reading its own content. Static findings are false positives from the scanner misinterpreting documentation code blocks and metadata as executable security risks.

2
Files scanned
376
Lines analyzed
2
Review items
0
False positives ignored
Audited by: claude

Jan 10, 2026, 10:57 AM

Pure documentation skill containing only markdown templates and guidance for React Native testing. No executable code, network access, or file system operations beyond reading its own content.

1
Files scanned
195
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 10, 2026, 10:57 AM

Pure documentation skill containing only markdown templates and guidance for React Native testing. No executable code, network access, or file system operations beyond reading its own content.

1
Files scanned
195
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 10, 2026, 10:57 AM

Pure documentation skill containing only markdown templates and guidance for React Native testing. No executable code, network access, or file system operations beyond reading its own content.

1
Files scanned
195
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude