Audit History
browser-extension-developer - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 8, 2026, 10:40 AM | No confirmed findings | 0 | No capability change |
| v7 | Jul 8, 2026, 10:40 AM | No confirmed findings | 0 | No capability change |
| v6 | Jul 1, 2026, 01:18 AM | No confirmed findings | 1 | No capability change |
| v5 | Jul 1, 2026, 01:18 AM | No confirmed findings | 1 | No capability change |
| v4 | Jan 17, 2026, 08:54 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 08:54 AM | No confirmed findings | 0 | External commands |
| v2 | Jan 4, 2026, 04:47 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 4, 2026, 04:47 PM | No confirmed findings | 0 | Baseline |
Jul 8, 2026, 10:40 AM
The static findings are false positives caused by Markdown backticks and documented npm commands in SKILL.md. I found no executable shell invocation, prompt injection attempt, or malicious intent in the skill text.
Risk Factors
⚙️ External commands (8)
Jul 8, 2026, 10:40 AM
The static findings are false positives caused by Markdown backticks and documented npm commands in SKILL.md. I found no executable shell invocation, prompt injection attempt, or malicious intent in the skill text.
Risk Factors
⚙️ External commands (8)
Jul 1, 2026, 01:18 AM
Static analysis flagged Markdown backticks as Ruby shell execution and weak cryptography. Review found no executable code, cryptographic implementation, prompt injection, network calls, or data exfiltration in SKILL.md. The only retained concern is low-risk guidance to run normal npm development commands in the target project.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (4)
Jul 1, 2026, 01:18 AM
Static analysis flagged Markdown backticks as Ruby shell execution and weak cryptography. Review found no executable code, cryptographic implementation, prompt injection, network calls, or data exfiltration in SKILL.md. The only retained concern is low-risk guidance to run normal npm development commands in the target project.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (4)
Jan 17, 2026, 08:54 AM
This skill contains only documentation files with no executable code, network calls, or filesystem access. The static analysis flagged markdown code fences and JSON content as security issues, but evaluation confirms these are false positives. SKILL.md provides guidance for WXT-based browser extension development.
Risk Factors
⚙️ External commands (9)
Jan 17, 2026, 08:54 AM
This skill contains only documentation files with no executable code, network calls, or filesystem access. The static analysis flagged markdown code fences and JSON content as security issues, but evaluation confirms these are false positives. SKILL.md provides guidance for WXT-based browser extension development.
Risk Factors
⚙️ External commands (9)
Jan 4, 2026, 04:47 PM
This skill contains only documentation files with no executable code, network calls, or filesystem access. It provides guidance for browser extension development but does not perform any actions that could compromise user security.
Jan 4, 2026, 04:47 PM
This skill contains only documentation files with no executable code, network calls, or filesystem access. It provides guidance for browser extension development but does not perform any actions that could compromise user security.