Audit History
drugbank-database - 12 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v12 Latest | Jul 9, 2026, 01:20 AM | No confirmed findings | 0 | No capability change |
| v11 | Jul 9, 2026, 01:20 AM | No confirmed findings | 0 | No capability change |
| v10 | Jul 9, 2026, 03:28 PM | 2 confirmed | 0 | No capability change |
| v9 | Jul 9, 2026, 01:20 AM | No confirmed findings | 0 | No capability change |
| v8 | Jul 8, 2026, 04:45 AM | 1 confirmed | 6 | No capability change |
| v7 | Jul 5, 2026, 10:32 AM | 2 confirmed | 0 | No capability change |
| v6 | Jun 29, 2026, 01:56 PM | No confirmed findings | 3 | External commands Contains scripts |
| v5 | Jan 17, 2026, 12:48 AM | No confirmed findings | 0 | No capability change |
| v4 | Jan 17, 2026, 12:48 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 7, 2026, 01:10 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 7, 2026, 01:10 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 7, 2026, 01:10 AM | No confirmed findings | 0 | Baseline |
Jul 9, 2026, 01:20 AM
Static findings are mostly documentation examples for DrugBank access, XML parsing, package installation, local caching, and namespace URLs. I found no prompt injection, credential exfiltration, malicious command execution, or hidden behavior; user-managed credentials and DrugBank API examples should still be documented clearly.
Risk Factors
🌐 Network access (33)
📁 Filesystem access (7)
🔑 Env variables (1)
⚙️ External commands (29)
Jul 9, 2026, 01:20 AM
Static findings are mostly documentation examples for DrugBank access, XML parsing, package installation, local caching, and namespace URLs. I found no prompt injection, credential exfiltration, malicious command execution, or hidden behavior; user-managed credentials and DrugBank API examples should still be documented clearly.
Risk Factors
🌐 Network access (33)
📁 Filesystem access (7)
🔑 Env variables (1)
⚙️ External commands (29)
Jul 9, 2026, 03:28 PM
Static findings were largely false positives from Markdown formatting, DrugBank XML namespace strings, local cache paths, and documented API examples. No prompt injection or malicious exfiltration intent was found. The main issues are documentation patterns that could expose credentials or encourage unsafe pickle cache loading.
Confirmed security concerns (2)
Risk Factors
🌐 Network access (33)
📁 Filesystem access (7)
🔑 Env variables (1)
⚙️ External commands (29)
Jul 9, 2026, 01:20 AM
Static findings are mostly documentation examples for DrugBank access, XML parsing, package installation, local caching, and namespace URLs. I found no prompt injection, credential exfiltration, malicious command execution, or hidden behavior; user-managed credentials and DrugBank API examples should still be documented clearly.
Risk Factors
🌐 Network access (33)
📁 Filesystem access (7)
🔑 Env variables (1)
⚙️ External commands (29)
Jul 8, 2026, 04:45 AM
Most static findings are false positives from XML namespace URLs, DrugBank identifiers, and Markdown backticks. Confirmed issues are expected but real: authenticated network access, hidden credential configuration, package installation, local cache writes, and unsafe pickle cache loading. No prompt injection evidence was found.
Confirmed security concerns (1)
Capability review items (6)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (33)
📁 Filesystem access (7)
🔑 Env variables (1)
⚙️ External commands (29)
Jul 5, 2026, 10:32 AM
Most static findings are false positives from Markdown examples, DrugBank XML namespaces, and domain-specific identifier names. No prompt injection, credential exfiltration, or malicious command execution intent was found. Two documentation risks remain: plaintext credential-file guidance and an unsafe pickle cache pattern.
Confirmed security concerns (2)
Risk Factors
🌐 Network access (33)
📁 Filesystem access (7)
🔑 Env variables (1)
⚙️ External commands (29)
Jun 29, 2026, 01:56 PM
Static analysis reported a critical combination of command, network, filesystem, and credential indicators, but review found no malicious intent or prompt injection. Most high alerts are false positives caused by markdown code fences, XML examples, SMILES and InChI chemistry terms, and PCA field names. The real risks are legitimate DrugBank network access, credential handling guidance, and local cache examples that require user caution.
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (167)
🌐 Network access (33)
📁 Filesystem access (7)
🔑 Env variables (1)
Detected Patterns
Jan 17, 2026, 12:48 AM
Legitimate bioinformatics research tool for accessing pharmaceutical data from DrugBank. Static findings are false positives from markdown documentation code blocks. All capabilities are consistent with stated purpose. Environment variable access is for authentication to DrugBank. Network access is to official DrugBank API endpoints. No malicious patterns detected.
Risk Factors
⚡ Contains scripts (1)
🌐 Network access (1)
📁 Filesystem access (1)
🔑 Env variables (1)
Jan 17, 2026, 12:48 AM
Legitimate bioinformatics research tool for accessing pharmaceutical data from DrugBank. Static findings are false positives from markdown documentation code blocks. All capabilities are consistent with stated purpose. Environment variable access is for authentication to DrugBank. Network access is to official DrugBank API endpoints. No malicious patterns detected.
Risk Factors
⚡ Contains scripts (1)
🌐 Network access (1)
📁 Filesystem access (1)
🔑 Env variables (1)
Jan 7, 2026, 01:10 AM
Legitimate scientific research tool for accessing pharmaceutical data from DrugBank. All capabilities are consistent with stated purpose. Environment variable access is for authentication to DrugBank. Network access is to official DrugBank API endpoints. No malicious patterns detected.
Risk Factors
⚡ Contains scripts (1)
🌐 Network access (1)
📁 Filesystem access (2)
🔑 Env variables (1)
Jan 7, 2026, 01:10 AM
Legitimate scientific research tool for accessing pharmaceutical data from DrugBank. All capabilities are consistent with stated purpose. Environment variable access is for authentication to DrugBank. Network access is to official DrugBank API endpoints. No malicious patterns detected.
Risk Factors
⚡ Contains scripts (1)
🌐 Network access (1)
📁 Filesystem access (2)
🔑 Env variables (1)
Jan 7, 2026, 01:10 AM
Legitimate scientific research tool for accessing pharmaceutical data from DrugBank. All capabilities are consistent with stated purpose. Environment variable access is for authentication to DrugBank. Network access is to official DrugBank API endpoints. No malicious patterns detected.