Audit History
gtars - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 23, 2026, 02:34 PM | No confirmed findings | 0 | No capability change |
| v8 | Jul 8, 2026, 07:03 AM | No confirmed findings | 0 | No capability change |
| v7 | Jul 5, 2026, 09:37 AM | No confirmed findings | 0 | Network access |
| v6 | Jun 29, 2026, 12:50 PM | 3 confirmed | 0 | Network access Contains scripts |
| v5 | Jan 17, 2026, 12:30 AM | No confirmed findings | 0 | No capability change |
| v4 | Jan 17, 2026, 12:30 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 7, 2026, 01:30 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 7, 2026, 01:30 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 7, 2026, 01:30 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 02:34 PM
All 47 static findings are false positives caused by Markdown formatting or benign Gtars documentation. The skill contains no executable scripts or injection text; examples describe expected local file operations, package installation, and an explicit BEDbase fetch.
Risk Factors
📁 Filesystem access (5)
⚙️ External commands (38)
Jul 8, 2026, 07:03 AM
The static findings are false positives from Markdown examples, inline reference links, and documented large-file memory mapping. I found no prompt injection, hidden command execution, credential access, or data exfiltration intent. The skill should still run install, cache, or file-processing commands only with user approval.
Risk Factors
📁 Filesystem access (5)
⚙️ External commands (38)
Jul 5, 2026, 09:37 AM
The static findings are false positives caused by Markdown examples, reference links, and documented genomic file workflows. Memory-mapped access is described only for user-selected genomic files, and command examples are explicit user-run gtars or install commands. No prompt injection, hidden execution intent, credential access, or data exfiltration evidence was found.
Risk Factors
📁 Filesystem access (5)
⚙️ External commands (38)
Jun 29, 2026, 12:50 PM
Static analysis reported many command, filesystem, and weak-crypto patterns, but most are Markdown examples for legitimate gtars usage. The remaining risk is medium because the skill encourages CLI execution, local file reads and writes, memory-mapped access, and BEDbase fetch/update workflows that can touch user data or the network.
Confirmed security concerns (3)
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (5)
📁 Filesystem access (4)
🌐 Network access (1)
Detected Patterns
Jan 17, 2026, 12:30 AM
This is a legitimate genomic interval analysis toolkit. All 187 static findings are false positives: bash command examples in documentation (misidentified as shell execution), standard cryptographic digests for the GA4GH refget protocol in bioinformatics, memory-mapped file access for efficient large file handling, and system info commands during installation. No malicious code patterns, network exfiltration, credential access, or obfuscation detected.
Risk Factors
⚡ Contains scripts (2)
📁 Filesystem access (2)
⚙️ External commands (2)
Jan 17, 2026, 12:30 AM
This is a legitimate genomic interval analysis toolkit. All 187 static findings are false positives: bash command examples in documentation (misidentified as shell execution), standard cryptographic digests for the GA4GH refget protocol in bioinformatics, memory-mapped file access for efficient large file handling, and system info commands during installation. No malicious code patterns, network exfiltration, credential access, or obfuscation detected.
Risk Factors
⚡ Contains scripts (2)
📁 Filesystem access (2)
⚙️ External commands (2)
Jan 7, 2026, 01:30 AM
This is a legitimate genomic interval analysis toolkit. All documentation describes standard bioinformatics operations. No malicious code patterns, network exfiltration, credential access, or obfuscation detected. The tool performs file I/O for genomic formats only.
Risk Factors
⚡ Contains scripts (2)
📁 Filesystem access (2)
⚙️ External commands (2)
Jan 7, 2026, 01:30 AM
This is a legitimate genomic interval analysis toolkit. All documentation describes standard bioinformatics operations. No malicious code patterns, network exfiltration, credential access, or obfuscation detected. The tool performs file I/O for genomic formats only.
Risk Factors
⚡ Contains scripts (2)
📁 Filesystem access (2)
⚙️ External commands (2)
Jan 7, 2026, 01:30 AM
This is a legitimate genomic interval analysis toolkit. All documentation describes standard bioinformatics operations. No malicious code patterns, network exfiltration, credential access, or obfuscation detected. The tool performs file I/O for genomic formats only.