Audit History
expo-tailwind-setup - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 5, 2026, 03:24 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 5, 2026, 03:24 PM | No confirmed findings | 0 | Contains scripts |
| v3 | Jun 30, 2026, 01:11 AM | No confirmed findings | 4 | External commandsNetwork accessEnv variables |
| v2 | Jan 23, 2026, 07:20 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 23, 2026, 07:06 AM | No confirmed findings | 0 | Baseline |
Jul 5, 2026, 03:24 PM
All static findings were adjudicated as false positives caused by Markdown code fences, sample configuration snippets, platform CSS references, or a benign Expo platform check. No prompt injection, credential access, data exfiltration, or malicious intent was found in SKILL.md.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (49)
🌐 Network access (1)
🔑 Env variables (2)
Jul 5, 2026, 03:24 PM
All static findings were adjudicated as false positives caused by Markdown code fences, sample configuration snippets, platform CSS references, or a benign Expo platform check. No prompt injection, credential access, data exfiltration, or malicious intent was found in SKILL.md.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (49)
🌐 Network access (1)
🔑 Env variables (2)
Jun 30, 2026, 01:11 AM
Static analysis reported many command execution, network, environment, and obfuscation patterns, but most matches are Markdown examples or benign Expo configuration snippets. No prompt injection, credential exfiltration, obfuscated payload, or malicious execution intent was found. The remaining publishable risk is supply-chain exposure because the guide tells users to install preview and nightly packages from the npm ecosystem.
Capability review items (4)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (1)
🌐 Network access (2)
🔑 Env variables (1)
Detected Patterns
Jan 23, 2026, 07:20 AM
Documentation-only skill containing setup instructions for Tailwind CSS v4 in Expo. All 65 static findings are false positives: backticks are markdown code blocks, URL is example image, environment access is platform detection. No executable code or credential access.
Jan 23, 2026, 07:06 AM
This is a read-only documentation file containing setup instructions for Tailwind CSS v4 in Expo. All 65 static findings are false positives: JSDoc type annotations were misidentified as dynamic imports, markdown code block delimiters were misidentified as shell commands, and legitimate environment variable access for platform detection was misidentified as credential access. No executable code, credential access, or command injection vectors exist.