Audit History
wcag-audit-patterns - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 8, 2026, 12:02 PM | No confirmed findings | 0 | No capability change |
| v6 | Jul 8, 2026, 12:02 PM | No confirmed findings | 0 | No capability change |
| v5 | Jul 1, 2026, 01:16 AM | 1 confirmed | 2 | No capability change |
| v4 | Jan 17, 2026, 08:43 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 08:43 AM | No confirmed findings | 0 | Network accessExternal commands |
| v2 | Jan 4, 2026, 04:41 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 4, 2026, 04:41 PM | No confirmed findings | 0 | Baseline |
Jul 8, 2026, 12:02 PM
All static findings are false positives caused by Markdown fences, accessibility examples, placeholder URLs, and resource links in SKILL.md. I found no executable code path, credential material, reconnaissance behavior, data exfiltration intent, or prompt injection text. The CLI examples should still be run only against approved targets.
Risk Factors
⚙️ External commands (45)
🌐 Network access (6)
Jul 8, 2026, 12:02 PM
All static findings are false positives caused by Markdown fences, accessibility examples, placeholder URLs, and resource links in SKILL.md. I found no executable code path, credential material, reconnaissance behavior, data exfiltration intent, or prompt injection text. The CLI examples should still be run only against approved targets.
Risk Factors
⚙️ External commands (45)
🌐 Network access (6)
Jul 1, 2026, 01:16 AM
Static analysis reported command execution, network, sensitive-key, weak-crypto, reconnaissance, and critical combination patterns. Manual review found the skill is a Markdown WCAG audit guide; the flagged items are fenced examples, accessibility tool commands, example URLs, and accessibility terms, with no executable payload or prompt injection found.
Confirmed security concerns (1)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (1)
🌐 Network access (2)
Detected Patterns
Jan 17, 2026, 08:43 AM
This is a pure documentation skill containing WCAG 2.2 audit guidance. No executable code, scripts, network calls, file access, or system interactions are present. The skill only contains markdown documentation with checklists and code examples for reference. All 86 static findings are false positives caused by the scanner misinterpreting markdown syntax (code block delimiters flagged as shell execution, section headers flagged as crypto algorithms, accessibility testing references flagged as reconnaissance).
Risk Factors
🌐 Network access (7)
⚙️ External commands (45)
Jan 17, 2026, 08:43 AM
This is a pure documentation skill containing WCAG 2.2 audit guidance. No executable code, scripts, network calls, file access, or system interactions are present. The skill only contains markdown documentation with checklists and code examples for reference. All 86 static findings are false positives caused by the scanner misinterpreting markdown syntax (code block delimiters flagged as shell execution, section headers flagged as crypto algorithms, accessibility testing references flagged as reconnaissance).
Risk Factors
🌐 Network access (7)
⚙️ External commands (45)
Jan 4, 2026, 04:41 PM
This is a pure documentation skill containing WCAG 2.2 audit guidance. No executable code, scripts, network calls, file access, or system interactions are present. The skill only contains markdown documentation with checklists and code examples for reference.
Jan 4, 2026, 04:41 PM
This is a pure documentation skill containing WCAG 2.2 audit guidance. No executable code, scripts, network calls, file access, or system interactions are present. The skill only contains markdown documentation with checklists and code examples for reference.