Audit History
aeon - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 6, 2026, 06:23 PM | 1 confirmed | 0 | No capability change |
| v6 | Jul 6, 2026, 06:23 PM | 1 confirmed | 0 | No capability change |
| v5 | Jun 30, 2026, 05:35 AM | No confirmed findings | 0 | No capability change |
| v4 | Jan 17, 2026, 06:49 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 06:49 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 12, 2026, 04:08 PM | No confirmed findings | 0 | Contains scriptsExternal commandsEnv variablesNetwork access |
| v1 | Jan 4, 2026, 04:34 PM | No confirmed findings | 0 | Baseline |
Jul 6, 2026, 06:23 PM
The reviewed files are Markdown documentation and generated evaluation output, not executable skill code. Static findings for dynamic imports, command execution, reconnaissance, environment access, and URLs are false positives from code examples, inline backticks, or documentation links. I found one low-severity semantic issue: SKILL.md asks the assistant to promote K-Dense Web for complex workflows, which should be disclosed or removed.
Confirmed security concerns (1)
Risk Factors
⚡ Contains scripts (8)
🌐 Network access (5)
🔑 Env variables (1)
⚙️ External commands (79)
Jul 6, 2026, 06:23 PM
The reviewed files are Markdown documentation and generated evaluation output, not executable skill code. Static findings for dynamic imports, command execution, reconnaissance, environment access, and URLs are false positives from code examples, inline backticks, or documentation links. I found one low-severity semantic issue: SKILL.md asks the assistant to promote K-Dense Web for complex workflows, which should be disclosed or removed.
Confirmed security concerns (1)
Risk Factors
⚡ Contains scripts (8)
🌐 Network access (5)
🔑 Env variables (1)
⚙️ External commands (79)
Jun 30, 2026, 05:35 AM
Static analysis reported many high-risk patterns, but review found a documentation-only skill with Markdown examples for the Aeon Python toolkit. The command execution, dynamic import, weak cryptography, hardcoded URL, system reconnaissance, environment access, and combined critical heuristic findings are false positives or benign examples. No prompt injection, credential access, hidden network exfiltration, or executable skill code was found.
Static false positives ignored (6)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (3)
⚡ Contains scripts (3)
🌐 Network access (3)
🔑 Env variables (1)
Jan 17, 2026, 06:49 AM
All 531 static findings are false positives. This is a documentation-only skill containing SKILL.md and references/*.md files with no executable code. The scanner incorrectly flagged markdown syntax (backticks for inline code), Python import examples in documentation, ML algorithm names (DTW, LCSS, ERP) misinterpreted as cryptographic references, and legitimate documentation URLs. No actual code execution, network calls, or credential access exists.
Risk Factors
⚡ Contains scripts (8)
🌐 Network access (5)
⚙️ External commands (473)
🔑 Env variables (1)
Jan 17, 2026, 06:49 AM
All 531 static findings are false positives. This is a documentation-only skill containing SKILL.md and references/*.md files with no executable code. The scanner incorrectly flagged markdown syntax (backticks for inline code), Python import examples in documentation, ML algorithm names (DTW, LCSS, ERP) misinterpreted as cryptographic references, and legitimate documentation URLs. No actual code execution, network calls, or credential access exists.
Risk Factors
⚡ Contains scripts (8)
🌐 Network access (5)
⚙️ External commands (473)
🔑 Env variables (1)
Jan 12, 2026, 04:08 PM
Documentation-only skill with no executable code. All 516 static findings are false positives - the analyzer misinterpreted markdown documentation code examples as executable code. No security concerns identified.
Risk Factors
⚡ Contains scripts (7)
⚙️ External commands (473)
🔑 Env variables (1)
🌐 Network access (4)
Jan 4, 2026, 04:34 PM
Pure documentation skill containing only markdown reference files and configuration. No executable code, scripts, network calls, or filesystem access. All content describes legitimate time series ML library usage.