Audit-Verlauf
matchms - 4 Audits
Audit-Version 4
Neueste SicherJan 17, 2026, 06:24 AM
All 268 static findings are false positives. The analyzer incorrectly flagged markdown code blocks (backticks) as shell execution, InChIKey descriptions as cryptographic algorithms, scientific database URLs as network reconnaissance, and legitimate Python code examples as malicious patterns. Matchms is a legitimate open-source mass spectrometry library for metabolomics research.
Risikofaktoren
⚡ Enthält Skripte (2)
⚙️ Externe Befehle (3)
🌐 Netzwerkzugriff (3)
📁 Dateisystemzugriff (1)
Audit-Version 3
SicherJan 17, 2026, 06:24 AM
All 268 static findings are false positives. The analyzer incorrectly flagged markdown code blocks (backticks) as shell execution, InChIKey descriptions as cryptographic algorithms, scientific database URLs as network reconnaissance, and legitimate Python code examples as malicious patterns. Matchms is a legitimate open-source mass spectrometry library for metabolomics research.
Risikofaktoren
⚡ Enthält Skripte (2)
⚙️ Externe Befehle (3)
🌐 Netzwerkzugriff (3)
📁 Dateisystemzugriff (1)
Audit-Version 2
SicherJan 12, 2026, 05:08 PM
The static analyzer incorrectly flagged documentation code blocks as security issues. All findings are false positives - the 'weak cryptographic algorithm' and 'external commands' alerts stem from markdown documentation containing code examples and legitimate URLs to scientific resources. No actual security risks were found.
Risikofaktoren
⚡ Enthält Skripte (1)
⚙️ Externe Befehle (1)
🌐 Netzwerkzugriff (1)
Audit-Version 1
SicherJan 4, 2026, 04:58 PM
Documentation-only skill containing markdown guides and code examples for the matchms Python library. No executable code, no credential access, no network exfiltration. Pure prompt-based guidance.