Audit History
market-research-reports - 5 audits
Audit version 5
Latest Low RiskJan 17, 2026, 01:28 AM
Legitimate market research skill. Static findings are false positives triggered by documentation patterns: LaTeX formatting commands (\samp), markdown code backticks, and relative file paths. The only actual code finding is subprocess.run() for internal visualization scripts, properly secured with list form (no shell injection risk). No network access, credential handling, or sensitive file operations.
High Risk Issues (1)
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (1)
Audit version 4
Low RiskJan 17, 2026, 01:28 AM
Legitimate market research skill. Static findings are false positives triggered by documentation patterns: LaTeX formatting commands (\samp), markdown code backticks, and relative file paths. The only actual code finding is subprocess.run() for internal visualization scripts, properly secured with list form (no shell injection risk). No network access, credential handling, or sensitive file operations.
High Risk Issues (1)
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (1)
Audit version 3
Low RiskJan 7, 2026, 12:38 AM
This is a legitimate market research skill with minimal risk. The Python script uses controlled subprocess calls to internal visualization scripts. No network access, no sensitive file access, no credential handling.
Low Risk Issues (1)
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (1)
Audit version 2
Low RiskJan 7, 2026, 12:38 AM
This is a legitimate market research skill with minimal risk. The Python script uses controlled subprocess calls to internal visualization scripts. No network access, no sensitive file access, no credential handling.
Low Risk Issues (1)
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (1)
Audit version 1
Low RiskJan 7, 2026, 12:38 AM
This is a legitimate market research skill with minimal risk. The Python script uses controlled subprocess calls to internal visualization scripts. No network access, no sensitive file access, no credential handling.