Audit History
frontend-security-coder - 5 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v5 Latest | Jul 23, 2026, 11:07 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 8, 2026, 10:15 AM | No confirmed findings | 0 | No capability change |
| v3 | Jul 6, 2026, 11:28 PM | No confirmed findings | 0 | External commands |
| v2 | Jun 30, 2026, 04:22 PM | No confirmed findings | 0 | No capability change |
| v1 | Feb 25, 2026, 01:27 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 11:07 PM
The only static finding is a false positive: line 24 uses Markdown backticks to identify a documentation path, not execute a shell command. No prompt injection, exfiltration intent, executable code, or other semantic security issue was found in the scanned skill.
Risk Factors
⚙️ External commands (1)
Jul 8, 2026, 10:15 AM
The static finding at SKILL.md line 24 is a false positive. It is a Markdown reference to an optional resource file, not shell execution. No prompt injection or semantic abuse evidence was found in the scanned file.
Risk Factors
⚙️ External commands (1)
Jul 6, 2026, 11:28 PM
The only static finding is a false positive: SKILL.md line 26 uses Markdown backticks to format a resource path, not shell execution. I found no evidence of prompt injection, data exfiltration intent, or other semantic security abuse in SKILL.md.
Risk Factors
⚙️ External commands (1)
Jun 30, 2026, 04:22 PM
Reviewed six static findings in SKILL.md and found no confirmed security issue. The detections are false positives caused by markdown backticks, browser security terminology, SAMEORIGIN text, and references to prevention topics. No evidence found of command execution, credential access, weak cryptography, data exfiltration, or prompt injection.
Static false positives ignored (6)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Feb 25, 2026, 01:27 AM
This is a prompt-only skill that generates frontend security content. No executable code was detected. The skill provides security guidance through natural language prompts without any system-level access, network calls, or file operations. Risk score is 0/100.