Audit History
angular - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 23, 2026, 07:11 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 8, 2026, 08:17 AM | No confirmed findings | 0 | No capability change |
| v3 | Jul 6, 2026, 08:10 PM | No confirmed findings | 0 | External commandsFilesystem access |
| v2 | Jun 30, 2026, 11:06 AM | No confirmed findings | 0 | Network accessContains scripts |
| v1 | Feb 24, 2026, 05:41 PM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 07:11 PM
All 102 static findings are false positives caused by documentation links, fenced Angular examples, Markdown backticks, or benign API names. The skill contains no executable scripts, unauthorized network behavior, filesystem access, system reconnaissance, or prompt injection intent.
Risk Factors
🌐 Network access (14)
⚡ Contains scripts (4)
⚙️ External commands (50)
📁 Filesystem access (1)
Jul 8, 2026, 08:17 AM
Reviewed 102 static findings across metadata.json and SKILL.md. The flagged network, script, external command, filesystem, and blocker patterns are documentation examples, reference links, or Angular syntax. No prompt injection or data exfiltration intent was found.
Risk Factors
🌐 Network access (14)
⚡ Contains scripts (4)
⚙️ External commands (81)
📁 Filesystem access (1)
Jul 6, 2026, 08:10 PM
All static findings were assessed as false positives in documentation or TypeScript examples. No evidence found of prompt injection, data exfiltration, command execution, filesystem access, or malicious intent in the reviewed files.
Risk Factors
🌐 Network access (14)
⚡ Contains scripts (4)
⚙️ External commands (81)
📁 Filesystem access (1)
Jun 30, 2026, 11:06 AM
Static analysis reported many high and medium findings, but review found they are documentation examples and reference links rather than executable skill code. No malicious intent, credential exfiltration, command execution path, or prompt injection attempt was found.
Static false positives ignored (4)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (5)
⚡ Contains scripts (2)
Feb 24, 2026, 05:41 PM
All static analysis findings were false positives. The skill contains documentation-only content (markdown and JSON configuration) with no executable code. URL references point to official Angular documentation. Markdown code formatting was incorrectly flagged as shell execution. No actual security risks detected.