Audit History
plotly - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 23, 2026, 03:17 PM | No confirmed findings | 0 | No capability change |
| v8 | Jul 8, 2026, 03:50 AM | No confirmed findings | 0 | No capability change |
| v7 | Jul 6, 2026, 09:40 AM | No confirmed findings | 0 | No capability change |
| v6 | Jun 29, 2026, 03:16 PM | 1 confirmed | 0 | No capability change |
| v5 | Jan 17, 2026, 12:55 AM | No confirmed findings | 0 | No capability change |
| v4 | Jan 17, 2026, 12:55 AM | No confirmed findings | 0 | External commandsFilesystem accessNetwork access |
| v3 | Jan 7, 2026, 01:06 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 7, 2026, 01:06 AM | No confirmed findings | 0 | No capability change |
| v1 | Jan 7, 2026, 01:06 AM | No confirmed findings | 0 | Baseline |
Jul 23, 2026, 03:17 PM
All 41 static findings are false positives caused by documentation examples, Markdown code fences, chart terminology, and official Plotly links. No malicious intent, prompt injection, unsafe command execution, unauthorized network activity, or dangerous file handling was found.
Risk Factors
📁 Filesystem access (1)
⚙️ External commands (29)
🌐 Network access (3)
Jul 8, 2026, 03:50 AM
The static analyzer raised file write, external command, network, and reconnaissance patterns, but review found documentation examples and reference links only. No prompt injection, credential access, command execution, or hidden network behavior was found in the reviewed files.
Risk Factors
📁 Filesystem access (1)
⚙️ External commands (29)
🌐 Network access (3)
Jul 6, 2026, 09:40 AM
All static findings were reviewed and appear to be documentation false positives. The matches are Markdown fences, Plotly examples, local chart export examples, and documentation links rather than executable behavior or data exfiltration. No prompt injection attempt or malicious intent was found in the reviewed files.
Risk Factors
📁 Filesystem access (1)
⚙️ External commands (29)
🌐 Network access (3)
Jun 29, 2026, 03:16 PM
Static analysis reported many high and medium alerts, but review found they are documentation false positives from markdown fences and Plotly terminology. No prompt injection, hidden exfiltration, or executable malware behavior was found. The remaining risk is low and limited to documented installs, local exports, CDN use, and external links.
Confirmed security concerns (1)
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (5)
📁 Filesystem access (5)
Jan 17, 2026, 12:55 AM
Documentation-only skill containing no executable code. All 318 static findings are FALSE POSITIVES. The skill consists entirely of markdown documentation with Python code examples for the Plotly visualization library. Pattern-based scanner incorrectly flagged markdown code fences (```python) as 'Ruby/shell backtick execution', common documentation words like 'Multiple' as 'C2 keywords', and legitimate documentation URLs as 'Hardcoded URL'. No scripts, network calls, file system access, or code execution capabilities exist in this skill.
Risk Factors
⚙️ External commands (293)
📁 Filesystem access (1)
🌐 Network access (3)
Jan 17, 2026, 12:55 AM
Documentation-only skill containing no executable code. All 318 static findings are FALSE POSITIVES. The skill consists entirely of markdown documentation with Python code examples for the Plotly visualization library. Pattern-based scanner incorrectly flagged markdown code fences (```python) as 'Ruby/shell backtick execution', common documentation words like 'Multiple' as 'C2 keywords', and legitimate documentation URLs as 'Hardcoded URL'. No scripts, network calls, file system access, or code execution capabilities exist in this skill.
Risk Factors
⚙️ External commands (293)
📁 Filesystem access (1)
🌐 Network access (3)
Jan 7, 2026, 01:06 AM
Documentation-only skill containing no executable code. Content consists entirely of markdown documentation and Python code examples demonstrating Plotly library usage. No scripts, network calls, file system access, or code execution capabilities.
Jan 7, 2026, 01:06 AM
Documentation-only skill containing no executable code. Content consists entirely of markdown documentation and Python code examples demonstrating Plotly library usage. No scripts, network calls, file system access, or code execution capabilities.
Jan 7, 2026, 01:06 AM
Documentation-only skill containing no executable code. Content consists entirely of markdown documentation and Python code examples demonstrating Plotly library usage. No scripts, network calls, file system access, or code execution capabilities.