Audit History
modern-javascript-patterns - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 8, 2026, 12:26 PM | No confirmed findings | 0 | No capability change |
| v8 | Jul 8, 2026, 12:26 PM | No confirmed findings | 0 | No capability change |
| v7 | Jul 1, 2026, 12:48 AM | No confirmed findings | 4 | No capability change |
| v6 | Jul 1, 2026, 12:48 AM | No confirmed findings | 4 | Contains scriptsNetwork accessExternal commands |
| v5 | Jan 21, 2026, 08:00 PM | No confirmed findings | 0 | Network accessContains scriptsExternal commands |
| v4 | Jan 17, 2026, 08:27 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 08:27 AM | No confirmed findings | 0 | Network accessContains scriptsExternal commands |
| v2 | Jan 4, 2026, 04:42 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 4, 2026, 04:42 PM | No confirmed findings | 0 | Baseline |
Jul 8, 2026, 12:26 PM
All static findings were assessed as false positives caused by Markdown fences, JavaScript template literals, educational fetch examples, import examples, and public resource links. No prompt injection, data exfiltration intent, hidden execution path, or host reconnaissance request was found in SKILL.md.
Risk Factors
⚡ Contains scripts (3)
⚙️ External commands (59)
🌐 Network access (9)
Jul 8, 2026, 12:26 PM
All static findings were assessed as false positives caused by Markdown fences, JavaScript template literals, educational fetch examples, import examples, and public resource links. No prompt injection, data exfiltration intent, hidden execution path, or host reconnaissance request was found in SKILL.md.
Risk Factors
⚡ Contains scripts (3)
⚙️ External commands (59)
🌐 Network access (9)
Jul 1, 2026, 12:48 AM
The static analyzer flagged dynamic imports, fetch calls, Markdown code fences, weak-crypto keywords, and reconnaissance-like terms. Review found these are documentation examples in SKILL.md, with no executable helper scripts, no prompt injection, and no evidence of malicious intent. The skill is safe to publish with low risk because users may copy network or dynamic import examples into their own projects.
Capability review items (4)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚡ Contains scripts (3)
🌐 Network access (9)
⚙️ External commands (59)
Jul 1, 2026, 12:48 AM
The static analyzer flagged dynamic imports, fetch calls, Markdown code fences, weak-crypto keywords, and reconnaissance-like terms. Review found these are documentation examples in SKILL.md, with no executable helper scripts, no prompt injection, and no evidence of malicious intent. The skill is safe to publish with low risk because users may copy network or dynamic import examples into their own projects.
Capability review items (4)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚡ Contains scripts (3)
🌐 Network access (9)
⚙️ External commands (59)
Jan 21, 2026, 08:00 PM
This is a documentation skill containing educational content about JavaScript ES6+ patterns. All static analysis findings are false positives. The 'weak cryptographic algorithm' flags are triggered by JavaScript template literals and class private field syntax (#). The 'shell backtick execution' flags are false positives from JavaScript template literals in code examples. The 'dynamic import()' detections are legitimate ES6 module examples being documented. No malicious code patterns exist.
Jan 17, 2026, 08:27 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
🌐 Network access (9)
⚡ Contains scripts (3)
⚙️ External commands (59)
Detected Patterns
Jan 17, 2026, 08:27 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
🌐 Network access (9)
⚡ Contains scripts (3)
⚙️ External commands (59)
Detected Patterns
Jan 4, 2026, 04:42 PM
The skill is a pure documentation guide containing educational JavaScript examples. It has no executable scripts, file access, network calls, or runtime code execution capabilities.
Jan 4, 2026, 04:42 PM
The skill is a pure documentation guide containing educational JavaScript examples. It has no executable scripts, file access, network calls, or runtime code execution capabilities.