Audit History
frontend-design - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 23, 2026, 10:52 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 8, 2026, 09:59 AM | No confirmed findings | 0 | No capability change |
| v3 | Jul 6, 2026, 11:07 PM | No confirmed findings | 0 | External commands |
| v2 | Jun 30, 2026, 04:06 PM | No confirmed findings | 0 | No capability change |
| v1 | Feb 25, 2026, 12:59 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 10:52 PM
All seven static findings are false positives. Lines 63 and 65 are Markdown fences around an arithmetic formula, while the remaining matches are ordinary design guidance. No prompt injection, command execution, reconnaissance, or malicious intent was found.
Risk Factors
⚙️ External commands (2)
Jul 8, 2026, 09:59 AM
All seven static findings are false positives. The two Ruby backtick alerts match Markdown code fences around a DFII formula, and the blocker alerts match frontend design prose rather than reconnaissance. No prompt injection, exfiltration intent, or unsafe automation was found in SKILL.md.
Risk Factors
⚙️ External commands (2)
Jul 6, 2026, 11:07 PM
All static findings appear to be false positives in a Markdown-only design instruction file. The backtick findings are fenced Markdown examples, and the reconnaissance findings are design language about typography, color, layout, and motion. No evidence of command execution, prompt injection, data exfiltration, or malicious intent was found.
Risk Factors
⚙️ External commands (2)
Jun 30, 2026, 04:06 PM
Static analysis reported network, external command, reconnaissance, and weak cryptography patterns. Manual review found these are false positives from Apache License text, markdown prose, and a fenced arithmetic formula, with no executable code or prompt injection found.
Static false positives ignored (4)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Feb 25, 2026, 12:59 AM
All 36 static analysis findings are false positives. The skill contains only markdown documentation describing a frontend design methodology (DFII framework). No executable code, network calls, or command execution present. The LICENSE.txt is standard Apache 2.0 text. Safe for publication.