Audit History
nx-workspace-patterns - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 8, 2026, 12:50 PM | 1 confirmed | 0 | No capability change |
| v7 | Jul 8, 2026, 12:50 PM | 1 confirmed | 0 | Env variables |
| v6 | Jul 1, 2026, 01:07 AM | No confirmed findings | 1 | No capability change |
| v5 | Jul 1, 2026, 01:07 AM | No confirmed findings | 1 | Env variables |
| v4 | Jan 17, 2026, 08:51 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 08:51 AM | No confirmed findings | 0 | Network accessExternal commandsFilesystem access |
| v2 | Jan 4, 2026, 04:50 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 4, 2026, 04:50 PM | No confirmed findings | 0 | Baseline |
Jul 8, 2026, 12:50 PM
All static findings were adjudicated as false positives because they are Markdown fences, inline examples, TypeScript template literals, documentation links, or normal Nx configuration references. No prompt injection or data exfiltration intent was found. One semantic issue remains: the remote cache guidance shows token fields directly in configuration, which could lead users to commit real secrets.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (25)
🌐 Network access (3)
📁 Filesystem access (3)
Jul 8, 2026, 12:50 PM
All static findings were adjudicated as false positives because they are Markdown fences, inline examples, TypeScript template literals, documentation links, or normal Nx configuration references. No prompt injection or data exfiltration intent was found. One semantic issue remains: the remote cache guidance shows token fields directly in configuration, which could lead users to commit real secrets.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (25)
🌐 Network access (3)
📁 Filesystem access (3)
Jul 1, 2026, 01:07 AM
Static analysis flagged 25 command, 3 URL, 4 filesystem, and 2 weak-crypto patterns. AI review found these to be false positives from Markdown examples, Nx configuration, resource links, and unrelated text. One low-risk content issue remains because cache token placeholders may encourage committed secrets.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (2)
🌐 Network access (1)
📁 Filesystem access (2)
🔑 Env variables (2)
Jul 1, 2026, 01:07 AM
Static analysis flagged 25 command, 3 URL, 4 filesystem, and 2 weak-crypto patterns. AI review found these to be false positives from Markdown examples, Nx configuration, resource links, and unrelated text. One low-risk content issue remains because cache token placeholders may encourage committed secrets.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (2)
🌐 Network access (1)
📁 Filesystem access (2)
🔑 Env variables (2)
Jan 17, 2026, 08:51 AM
This skill contains only static documentation and configuration templates for Nx workspaces. All 41 static findings are false positives: network URLs are legitimate metadata/doc links, external commands are example bash commands in documentation code blocks, path traversal sequences are standard relative paths in JSON config examples, and cryptographic alerts are misidentified schema file paths. The skill has no executable code, no file operations, no data handling, and no network access capability.
Risk Factors
🌐 Network access (3)
⚙️ External commands (25)
📁 Filesystem access (4)
Jan 17, 2026, 08:51 AM
This skill contains only static documentation and configuration templates for Nx workspaces. All 41 static findings are false positives: network URLs are legitimate metadata/doc links, external commands are example bash commands in documentation code blocks, path traversal sequences are standard relative paths in JSON config examples, and cryptographic alerts are misidentified schema file paths. The skill has no executable code, no file operations, no data handling, and no network access capability.
Risk Factors
🌐 Network access (3)
⚙️ External commands (25)
📁 Filesystem access (4)
Jan 4, 2026, 04:50 PM
This skill contains only static documentation and configuration templates for Nx workspaces. No executable code, network access, file operations, or data handling is present.
Jan 4, 2026, 04:50 PM
This skill contains only static documentation and configuration templates for Nx workspaces. No executable code, network access, file operations, or data handling is present.