Audit History
React Native Mobile Development - 12 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v12 Latest | Jul 18, 2026, 10:18 AM | No confirmed findings | 0 | No capability change |
| v11 | Jul 17, 2026, 10:31 AM | No confirmed findings | 0 | No capability change |
| v10 | Jul 17, 2026, 10:31 AM | No confirmed findings | 0 | No capability change |
| v9 | Jul 17, 2026, 10:31 AM | No confirmed findings | 0 | No capability change |
| v8 | Jul 5, 2026, 05:05 AM | No confirmed findings | 0 | No capability change |
| v7 | Jul 5, 2026, 05:05 AM | No confirmed findings | 0 | Filesystem access |
| v6 | Jun 28, 2026, 01:09 PM | 1 confirmed | 2 | Filesystem access |
| v5 | Jan 16, 2026, 05:13 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 05:13 PM | No confirmed findings | 0 | Network accessExternal commands |
| v3 | Jan 10, 2026, 11:02 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 11:02 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 11:02 AM | No confirmed findings | 0 | Baseline |
Jul 18, 2026, 10:18 AM
All 20 static detections are false positives caused by Markdown fences, inline code, documentation links, and ordinary mobile development instructions. The skill contains no prompt-injection language, data-exfiltration intent, hidden commands, or system reconnaissance.
Risk Factors
⚙️ External commands (16)
🌐 Network access (2)
Jul 17, 2026, 10:31 AM
All 20 static findings are false positives. The command-like matches are Markdown fences, API names, or optional local React Native and Expo commands; the URLs link only to official documentation. No prompt injection, data exfiltration, or malicious intent was found in SKILL.md.
Risk Factors
⚙️ External commands (16)
🌐 Network access (2)
Jul 17, 2026, 10:31 AM
All 20 static findings are false positives. The command-like matches are Markdown fences, API names, or optional local React Native and Expo commands; the URLs link only to official documentation. No prompt injection, data exfiltration, or malicious intent was found in SKILL.md.
Risk Factors
⚙️ External commands (16)
🌐 Network access (2)
Jul 17, 2026, 10:31 AM
All 20 static findings are false positives. The command-like matches are Markdown fences, API names, or optional local React Native and Expo commands; the URLs link only to official documentation. No prompt injection, data exfiltration, or malicious intent was found in SKILL.md.
Risk Factors
⚙️ External commands (16)
🌐 Network access (2)
Jul 5, 2026, 05:05 AM
All static findings were false positives caused by Markdown code fences, inline API names, fixed npm or Expo command examples, and official documentation links. I found no evidence of prompt injection, hidden command execution, data exfiltration, or malicious intent in SKILL.md.
Risk Factors
⚙️ External commands (16)
🌐 Network access (2)
Jul 5, 2026, 05:05 AM
All static findings were false positives caused by Markdown code fences, inline API names, fixed npm or Expo command examples, and official documentation links. I found no evidence of prompt injection, hidden command execution, data exfiltration, or malicious intent in SKILL.md.
Risk Factors
⚙️ External commands (16)
🌐 Network access (2)
Jun 28, 2026, 01:09 PM
Static analysis flagged external command examples, documentation URLs, and several blocker patterns. Review found no prompt injection, malicious intent, credential access, or data exfiltration; the weak cryptography and system reconnaissance matches are false positives. The remaining risk is that the skill permits Bash and file edits while recommending npm, npx, Expo, iOS, and Android commands that can execute project scripts or install third-party packages.
Confirmed security concerns (1)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (2)
🌐 Network access (1)
📁 Filesystem access (1)
Detected Patterns
Jan 16, 2026, 05:13 PM
Documentation-only skill for React Native development. Contains no executable code, scripts, or file system operations. Static findings are false positives from markdown documentation elements (color codes, bash examples, external links) that the scanner misidentified as security risks.
Risk Factors
🌐 Network access (2)
Jan 16, 2026, 05:13 PM
Documentation-only skill for React Native development. Contains no executable code, scripts, or file system operations. Static findings are false positives from markdown documentation elements (color codes, bash examples, external links) that the scanner misidentified as security risks.
Risk Factors
🌐 Network access (2)
Jan 10, 2026, 11:02 AM
This is a documentation-only skill containing guidance, code patterns, and best practices for React Native development. No executable code, scripts, network activity, or file system access beyond its own documentation file.
Jan 10, 2026, 11:02 AM
This is a documentation-only skill containing guidance, code patterns, and best practices for React Native development. No executable code, scripts, network activity, or file system access beyond its own documentation file.
Jan 10, 2026, 11:02 AM
This is a documentation-only skill containing guidance, code patterns, and best practices for React Native development. No executable code, scripts, network activity, or file system access beyond its own documentation file.