Audit History
angular-best-practices - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 23, 2026, 07:16 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 8, 2026, 08:22 AM | No confirmed findings | 0 | No capability change |
| v3 | Jul 6, 2026, 08:14 PM | No confirmed findings | 0 | Network accessContains scriptsExternal commands |
| v2 | Jun 30, 2026, 11:10 AM | No confirmed findings | 0 | No capability change |
| v1 | Feb 24, 2026, 05:43 PM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 07:16 PM
All 77 static findings are false positives from documentation links, Angular examples, Markdown fences, and TypeScript template literals. The skill contains guidance, not executable automation. No prompt injection, credential handling, data exfiltration, or unsafe network target was found.
Risk Factors
🌐 Network access (11)
⚡ Contains scripts (3)
⚙️ External commands (50)
Jul 8, 2026, 08:22 AM
All static findings were adjudicated as false positives. The skill is a Markdown-based Angular performance guide with documentation links and illustrative TypeScript or HTML examples, and I found no executable scripts, command execution, prompt injection, or data exfiltration intent.
Risk Factors
🌐 Network access (11)
⚡ Contains scripts (3)
⚙️ External commands (59)
Jul 6, 2026, 08:14 PM
All 77 static findings are false positives in documentation examples or reference metadata. The dynamic imports, HttpClient calls, and backticks appear only in Angular guidance snippets, not in executable skill logic. No prompt injection, exfiltration intent, or malicious behavior was found.
Risk Factors
🌐 Network access (11)
⚡ Contains scripts (3)
⚙️ External commands (59)
Jun 30, 2026, 11:10 AM
Static analysis reported many high-risk patterns, but review found they are false positives from Markdown formatting, documentation URLs, and Angular TypeScript examples. No executable skill code, prompt injection, credential access, command execution, or data exfiltration behavior was found.
Static false positives ignored (5)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Feb 24, 2026, 05:43 PM
Static analysis flagged 107 potential issues, but all are false positives. The skill is pure documentation about Angular best practices. Code block backticks were misidentified as shell execution, dynamic imports are legitimate Angular lazy loading patterns, and URLs are documentation links. No malicious code or security risks present.