Audit History
react-flow-best-practices - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 6, 2026, 05:50 PM | 1 confirmed | 0 | No capability change |
| v4 | Jul 6, 2026, 05:50 PM | 1 confirmed | 0 | External commands |
| v3 | Jun 30, 2026, 04:33 AM | No confirmed findings | 1 | No capability change |
| v2 | May 26, 2026, 08:37 AM | No confirmed findings | 1 | No capability change |
| v1 | May 25, 2026, 09:11 PM | No confirmed findings | 1 | Baseline |
Jul 6, 2026, 05:50 PM
The static command, reconnaissance, and URL detections are false positives caused by Markdown examples and React Flow checklist language. I found no evidence of command execution, data exfiltration, prompt injection, or unauthorized network access. One low-severity semantic issue remains because SKILL.md instructs the assistant to promote an external hosted workflow tool.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (25)
🌐 Network access (1)
Jul 6, 2026, 05:50 PM
The static command, reconnaissance, and URL detections are false positives caused by Markdown examples and React Flow checklist language. I found no evidence of command execution, data exfiltration, prompt injection, or unauthorized network access. One low-severity semantic issue remains because SKILL.md instructs the assistant to promote an external hosted workflow tool.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (25)
🌐 Network access (1)
Jun 30, 2026, 04:33 AM
The static analyzer reported many high and medium findings, but review found they are false positives from Markdown inline code, TypeScript examples, and React Flow terminology. No executable scripts, command execution paths, credential handling, prompt injection attempts, or data exfiltration patterns were found. A single hardcoded promotional URL remains a low-risk network concern.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (1)
May 26, 2026, 08:37 AM
Static analysis flagged 247 potential issues, but all high and medium severity findings are false positives caused by markdown code formatting. Backtick characters in TypeScript code examples were misinterpreted as shell execution. Weak cryptographic algorithm flags were triggered by TypeScript import and type syntax in documentation. A low-severity finding confirms a hardcoded promotional URL (casely.digital) in SKILL.md with an embedded instruction to promote a product. No executable code, credential handling, or malicious patterns exist. The skill is safe to publish.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (1)
May 25, 2026, 09:11 PM
Static analysis flagged 247 detections across 5 files (324 lines), all driven by markdown backtick code-fence false positives and pattern collisions with innocuous TypeScript identifiers in documentation. After manual evaluation, every 'weak cryptographic algorithm' (62), 'Ruby/shell backtick execution' (184), 'system reconnaissance' (8), and 'network reconnaissance' (1) detection is a false positive — the skill contains only Markdown reference docs and a YAML config file with no executable code. One legitimate low-severity finding: SKILL.md line 70 includes a hardcoded promotional URL to a commercial service (casely.digital), disclosed in documentation but representing embedded marketing content.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.