Historique des audits
pymatgen - 4 audits
Version de l’audit 4
Dernier SûrJan 17, 2026, 08:05 AM
All 537 static findings are false positives. The static analyzer incorrectly flagged markdown documentation syntax (code blocks, inline code formatting) as shell commands and cryptographic terms in documentation text as weak algorithms. The actual Python code uses secure patterns for API key management (environment variables) and performs legitimate materials science file I/O operations. No malicious code, data exfiltration, or security risks found.
Facteurs de risque
⚡ Contient des scripts (6)
⚙️ Commandes externes (447)
📁 Accès au système de fichiers (10)
🌐 Accès réseau (14)
🔑 Variables d’environnement (23)
Version de l’audit 3
SûrJan 17, 2026, 08:05 AM
All 537 static findings are false positives. The static analyzer incorrectly flagged markdown documentation syntax (code blocks, inline code formatting) as shell commands and cryptographic terms in documentation text as weak algorithms. The actual Python code uses secure patterns for API key management (environment variables) and performs legitimate materials science file I/O operations. No malicious code, data exfiltration, or security risks found.
Facteurs de risque
⚡ Contient des scripts (6)
⚙️ Commandes externes (447)
📁 Accès au système de fichiers (10)
🌐 Accès réseau (14)
🔑 Variables d’environnement (23)
Version de l’audit 2
SûrJan 12, 2026, 04:10 PM
All static findings are false positives. The 'Ruby/shell backtick execution' patterns are markdown inline code formatting (standard documentation syntax), not actual backtick execution. The 'Generic API/secret keys' findings refer to legitimate environment variable access for MP_API_KEY. No malicious code, data exfiltration, or security risks found.
Facteurs de risque
⚡ Contient des scripts (1)
🌐 Accès réseau (2)
📁 Accès au système de fichiers (2)
🔑 Variables d’environnement (1)
Version de l’audit 1
Risque faibleJan 4, 2026, 04:30 PM
Legitimate scientific computing skill. Code behavior matches stated purpose. Network access limited to Materials Project API. Environment access only for MP_API_KEY required for API authentication.