Audit History
sast-bandit - 10 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v10 Latest | Jul 23, 2026, 06:28 AM | 2 confirmed | 3 | No capability change |
| v9 | Jul 7, 2026, 09:39 PM | No confirmed findings | 0 | No capability change |
| v8 | Jul 5, 2026, 03:09 AM | No confirmed findings | 1 | No capability change |
| v7 | Jul 5, 2026, 03:09 AM | No confirmed findings | 1 | No capability change |
| v6 | Jun 28, 2026, 06:05 AM | No confirmed findings | 4 | No capability change |
| v5 | Jan 16, 2026, 04:02 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 16, 2026, 04:02 PM | No confirmed findings | 0 | Contains scriptsExternal commandsFilesystem accessNetwork accessEnv variables |
| v3 | Jan 10, 2026, 10:56 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 10, 2026, 10:56 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 10, 2026, 10:56 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 06:28 AM
Most static matches are false positives from configuration lists, Markdown formatting, references, and labeled vulnerable examples. Confirmed risks include unsafe eval suppression, unvalidated subprocess guidance, fragile xargs filename handling, and unsafe pickle suppression. Third-party hooks and actions also use mutable references.
Confirmed security concerns (2)
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚡ Contains scripts (2)
⚙️ External commands (50)
📁 Filesystem access (15)
🌐 Network access (29)
🔑 Env variables (19)
Jul 7, 2026, 09:39 PM
The static findings are explained by Bandit configuration, pre-commit templates, and Markdown remediation examples. No evidence found of malicious intent, prompt injection, active secret access, or hidden data exfiltration in the reviewed files.
Risk Factors
⚡ Contains scripts (2)
⚙️ External commands (61)
📁 Filesystem access (15)
🌐 Network access (29)
🔑 Env variables (19)
Jul 5, 2026, 03:09 AM
Reviewed all 150 static detections in context. Nearly all are false positives from Markdown formatting, Bandit configuration data, public dependency references, or explicitly labeled vulnerable examples in remediation docs. One changed-file xargs pipeline remains a medium-confidence operational risk because unusual repository filenames can affect command invocation.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (4)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚡ Contains scripts (2)
⚙️ External commands (61)
📁 Filesystem access (15)
🌐 Network access (29)
🔑 Env variables (19)
Jul 5, 2026, 03:09 AM
Reviewed all 150 static detections in context. Nearly all are false positives from Markdown formatting, Bandit configuration data, public dependency references, or explicitly labeled vulnerable examples in remediation docs. One changed-file xargs pipeline remains a medium-confidence operational risk because unusual repository filenames can affect command invocation.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (4)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚡ Contains scripts (2)
⚙️ External commands (61)
📁 Filesystem access (15)
🌐 Network access (29)
🔑 Env variables (19)
Jun 28, 2026, 06:05 AM
Static analysis reported many high and critical patterns, but manual review shows they are mostly Bandit rule names, scanner configuration, or vulnerable examples inside documentation. The skill is publishable with a medium warning because it asks users to install and run local security tooling, may scan broad source trees, and may produce reports containing sensitive code snippets.
Capability review items (4)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (4)
⚡ Contains scripts (3)
📁 Filesystem access (3)
🌐 Network access (3)
🔑 Env variables (2)
Detected Patterns
Jan 16, 2026, 04:02 PM
Documentation-only skill containing YAML configs and Markdown guides for Bandit SAST tool. All 257 static findings are FALSE POSITIVES - the skill shows VULNERABLE code patterns as examples of what Bandit DETECTS, not actual malicious code. No executable scripts found. Purely defensive security documentation.
Risk Factors
⚡ Contains scripts (2)
⚙️ External commands (120)
📁 Filesystem access (15)
🌐 Network access (35)
🔑 Env variables (22)
Jan 16, 2026, 04:02 PM
Documentation-only skill containing YAML configs and Markdown guides for Bandit SAST tool. All 257 static findings are FALSE POSITIVES - the skill shows VULNERABLE code patterns as examples of what Bandit DETECTS, not actual malicious code. No executable scripts found. Purely defensive security documentation.
Risk Factors
⚡ Contains scripts (2)
⚙️ External commands (120)
📁 Filesystem access (15)
🌐 Network access (35)
🔑 Env variables (22)
Jan 10, 2026, 10:56 AM
Documentation and configuration-only skill for Bandit SAST tool. No executable scripts found. Contains YAML configs, remediation guides, and security framework mappings. Purely informational with no code execution capabilities.
Jan 10, 2026, 10:56 AM
Documentation and configuration-only skill for Bandit SAST tool. No executable scripts found. Contains YAML configs, remediation guides, and security framework mappings. Purely informational with no code execution capabilities.
Jan 10, 2026, 10:56 AM
Documentation and configuration-only skill for Bandit SAST tool. No executable scripts found. Contains YAML configs, remediation guides, and security framework mappings. Purely informational with no code execution capabilities.