Audit History
tailwind-design-system - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 8, 2026, 02:37 PM | No confirmed findings | 0 | No capability change |
| v6 | Jul 8, 2026, 02:37 PM | No confirmed findings | 0 | External commands |
| v5 | Jul 1, 2026, 12:45 AM | 1 confirmed | 1 | External commands |
| v4 | Jan 17, 2026, 10:38 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 10:38 AM | No confirmed findings | 0 | Network accessExternal commands |
| v2 | Jan 4, 2026, 04:31 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 4, 2026, 04:31 PM | No confirmed findings | 0 | Baseline |
Jul 8, 2026, 02:37 PM
All static findings are false positives caused by Markdown fences, JSX template literals, Tailwind class examples, and passive documentation links. No prompt injection, data exfiltration intent, or executable command behavior was found in SKILL.md.
Risk Factors
⚙️ External commands (25)
🌐 Network access (4)
Jul 8, 2026, 02:37 PM
All static findings are false positives caused by Markdown fences, JSX template literals, Tailwind class examples, and passive documentation links. No prompt injection, data exfiltration intent, or executable command behavior was found in SKILL.md.
Risk Factors
⚙️ External commands (25)
🌐 Network access (4)
Jul 1, 2026, 12:45 AM
Static analysis reported command execution, weak cryptography, browser storage, system reconnaissance, network links, and a critical heuristic combination. Manual review found these are documentation examples and Markdown syntax, with no executable scripts, credential access, or malicious instructions. The only retained concern is low-risk outbound documentation links and example localStorage use for theme preference.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (4)
Detected Patterns
Jan 17, 2026, 10:38 AM
Pure documentation skill with no executable code. Contains only markdown guidance and code examples for Tailwind CSS design systems. The static analyzer's 100/100 risk score is a false positive caused by misinterpreting Tailwind CSS opacity syntax (e.g., bg-primary/90) as cryptographic algorithms, and TypeScript template literals as shell backticks.
Risk Factors
🌐 Network access (4)
⚙️ External commands (25)
Jan 17, 2026, 10:38 AM
Pure documentation skill with no executable code. Contains only markdown guidance and code examples for Tailwind CSS design systems. The static analyzer's 100/100 risk score is a false positive caused by misinterpreting Tailwind CSS opacity syntax (e.g., bg-primary/90) as cryptographic algorithms, and TypeScript template literals as shell backticks.
Risk Factors
🌐 Network access (4)
⚙️ External commands (25)
Jan 4, 2026, 04:31 PM
Pure documentation skill with no executable code. Contains only markdown guidance and code examples for Tailwind CSS design systems. No file access, network calls, or command execution detected.
Jan 4, 2026, 04:31 PM
Pure documentation skill with no executable code. Contains only markdown guidance and code examples for Tailwind CSS design systems. No file access, network calls, or command execution detected.