Audit History
baseline-ui - 6 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v6 Latest | Jul 23, 2026, 06:35 PM | No confirmed findings | 0 | No capability change |
| v5 | Jul 8, 2026, 02:13 AM | No confirmed findings | 0 | No capability change |
| v4 | Jul 6, 2026, 02:31 PM | No confirmed findings | 0 | External commands |
| v3 | Jun 30, 2026, 04:14 AM | 1 confirmed | 0 | Network access |
| v2 | Feb 10, 2026, 09:04 AM | No confirmed findings | 0 | No capability change |
| v1 | Feb 9, 2026, 09:02 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 06:35 PM
All 30 static findings are false positives caused by Markdown inline code, a documentation hyperlink, and ordinary UI terminology. SKILL.md contains frontend review guidance without executable scripts, network requests, system reconnaissance, credential access, or prompt injection. No semantic security findings were identified.
Risk Factors
⚙️ External commands (27)
🌐 Network access (1)
Jul 8, 2026, 02:13 AM
All static findings were adjudicated as false positives. The file is Markdown guidance for frontend UI review, and the flagged backticks are inline formatting rather than executable commands.
Risk Factors
⚙️ External commands (27)
🌐 Network access (1)
Jul 6, 2026, 02:31 PM
All static findings are false positives caused by Markdown examples, inline package names, CSS utility names, and prose. No runtime code, shell execution, network request, system reconnaissance, data exfiltration, or prompt injection intent was found in SKILL.md.
Risk Factors
⚙️ External commands (27)
🌐 Network access (1)
Jun 30, 2026, 04:14 AM
Static analysis flagged many external command and weak cryptography patterns, but these are false positives from Markdown inline code and ordinary UI terms. The skill contains documentation-only guidance and no executable scripts, shell commands, credential access, data exfiltration, or prompt injection. One external documentation link is present, so the final risk is low and safe to publish.
Confirmed security concerns (1)
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (1)
Feb 10, 2026, 09:04 AM
All 54 static findings are FALSE POSITIVES. The scanner misinterpreted Markdown documentation syntax (backtick characters) as Ruby shell commands and UI terminology as security threats. This skill is pure documentation with no executable code, network requests, or security risks.
Static false positives ignored (4)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Feb 9, 2026, 09:02 AM
All static findings are false positives. SKILL.md is a text-based UI guideline document containing only markdown documentation with inline code references. No executable code, command execution, network requests, or cryptographic operations exist. The skill is purely informational guidance.