Audit History
wrangler - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 5, 2026, 12:00 PM | 1 confirmed | 0 | No capability change |
| v8 | Jul 5, 2026, 12:00 PM | 1 confirmed | 0 | No capability change |
| v7 | Jun 29, 2026, 05:13 PM | No confirmed findings | 3 | No capability change |
| v6 | Jan 21, 2026, 05:32 PM | No confirmed findings | 0 | No capability change |
| v5 | Jan 17, 2026, 03:28 AM | No confirmed findings | 0 | No capability change |
| v4 | Jan 17, 2026, 03:28 AM | No confirmed findings | 0 | External commands |
| v3 | Jan 10, 2026, 02:02 PM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 02:02 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 02:02 PM | No confirmed findings | 0 | Baseline |
Jul 5, 2026, 12:00 PM
The static Ruby backtick findings are false positives caused by Markdown inline code and fenced bash examples in SKILL.md. No prompt injection attempt or hidden executable source code was found. The skill is a legitimate Wrangler command reference, but several examples can modify Cloudflare resources or handle secrets and should require user confirmation.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (41)
Jul 5, 2026, 12:00 PM
The static Ruby backtick findings are false positives caused by Markdown inline code and fenced bash examples in SKILL.md. No prompt injection attempt or hidden executable source code was found. The skill is a legitimate Wrangler command reference, but several examples can modify Cloudflare resources or handle secrets and should require user confirmation.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (41)
Jun 29, 2026, 05:13 PM
The static Ruby backtick and weak cryptography findings are false positives caused by Markdown code fences, inline backticks, and Cloudflare product names. The skill is a legitimate Wrangler CLI reference, but many documented commands can change Cloudflare production resources, query data, upload files, deploy applications, or set secrets when used with an authenticated account.
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (41)
Detected Patterns
Jan 21, 2026, 05:32 PM
All static findings are false positives. The skill provides documentation for the legitimate Cloudflare wrangler CLI tool. Detected patterns (command references, infrastructure listings, crypto mentions) are standard devops documentation content, not malicious code. This is a legitimate infrastructure management skill with no security concerns.
Risk Factors
⚙️ External commands (41)
Jan 17, 2026, 03:28 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
⚙️ External commands (41)
Detected Patterns
Jan 17, 2026, 03:28 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
⚙️ External commands (41)
Detected Patterns
Jan 10, 2026, 02:02 PM
This skill contains only documentation in SKILL.md. No executable code, scripts, network operations, file system access, or environment variable reads were detected. Pure prompt-based skill with zero attack surface.
Jan 10, 2026, 02:02 PM
This skill contains only documentation in SKILL.md. No executable code, scripts, network operations, file system access, or environment variable reads were detected. Pure prompt-based skill with zero attack surface.
Jan 10, 2026, 02:02 PM
This skill contains only documentation in SKILL.md. No executable code, scripts, network operations, file system access, or environment variable reads were detected. Pure prompt-based skill with zero attack surface.