Audit History
expo-dev-client - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 5, 2026, 03:20 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 5, 2026, 03:20 PM | No confirmed findings | 0 | No capability change |
| v3 | Jun 30, 2026, 01:08 AM | No confirmed findings | 2 | No capability change |
| v2 | Jan 23, 2026, 07:20 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 23, 2026, 07:06 AM | No confirmed findings | 0 | Baseline |
Jul 5, 2026, 03:20 PM
The static findings are false positives caused by Markdown inline code and fenced command examples in SKILL.md. The skill documents legitimate Expo and EAS development client workflows, and no prompt injection, exfiltration intent, or hidden automation was found.
Risk Factors
⚙️ External commands (30)
Jul 5, 2026, 03:20 PM
The static findings are false positives caused by Markdown inline code and fenced command examples in SKILL.md. The skill documents legitimate Expo and EAS development client workflows, and no prompt injection, exfiltration intent, or hidden automation was found.
Risk Factors
⚙️ External commands (30)
Jun 30, 2026, 01:08 AM
Static analysis flagged many backtick and command examples in SKILL.md. Review found these are Markdown instructions for Expo EAS, simulator, device, and Android tooling, not hidden executable code or malicious automation. The skill is publishable with a medium warning because it instructs users to run external commands that can build, install, update tooling, and submit iOS builds.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (31)
Detected Patterns
Jan 23, 2026, 07:20 AM
All 38 static findings evaluated as false positives. The skill contains legitimate documentation for Expo EAS CLI commands and standard development workflows. No malicious patterns, command injection vectors, or data exfiltration detected.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (31)
Jan 23, 2026, 07:06 AM
All 38 static findings are false positives. External command detections are legitimate Expo/EAS CLI commands for development workflows. No malicious patterns, credential exfiltration, or security risks identified. The skill contains only documentation for standard build commands.