Audit History
starknet-js - 3 audits
Version comparison
Capability and finding changes across audited versions, newest first.
Aug 7, 2026, 09:06 AM
All 99 static findings are false positives after contextual review. The matches describe documentation syntax, public RPC examples, relative references, standard configuration access, or intentional environment-based key loading; no command execution, exfiltration, or prompt injection was identified.
Risk Factors
⚙️ External commands (50)
🔑 Env variables (5)
🌐 Network access (6)
📁 Filesystem access (1)
Jul 21, 2026, 04:37 AM
All 99 static findings are false positives: they identify Markdown fences, documentation links, public endpoint examples, normal signer handling, or non-sensitive configuration access. No prompt injection, secret exfiltration, command execution, or hidden network behavior was found. The documentation should add consistent user-confirmation guidance before state-changing transactions.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (50)
🔑 Env variables (5)
🌐 Network access (6)
📁 Filesystem access (1)
Jul 10, 2026, 12:27 AM
AI review confirmed six static findings in scripts/account-example.ts related to environment access and raw Starknet private-key handling. The remaining static findings are false positives from Markdown formatting, documentation URLs, reference links, or normal Starknet API examples, and no prompt injection was found. One semantic finding notes overbroad tool permissions in the skill metadata.
Confirmed security concerns (3)
Capability review items (4)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.