Audit History
alphafold-database - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 5, 2026, 06:04 PM | 2 confirmed | 1 | No capability change |
| v6 | Jul 5, 2026, 06:04 PM | 2 confirmed | 1 | No capability change |
| v5 | Jun 30, 2026, 05:38 AM | 1 confirmed | 4 | No capability change |
| v4 | Jan 17, 2026, 06:50 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 06:50 AM | No confirmed findings | 0 | Filesystem access |
| v2 | Jan 12, 2026, 04:10 PM | No confirmed findings | 0 | Network accessExternal commands |
| v1 | Jan 5, 2026, 03:47 PM | No confirmed findings | 0 | Baseline |
Jul 5, 2026, 06:04 PM
Most static findings are false positives from Markdown code fences, public API URLs, and scientific data examples. One confirmed critical issue remains: the API reference recommends piping a remote installer directly to bash. A semantic review also found publisher-benefiting steering toward K-Dense Web.
Confirmed security concerns (2)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (40)
🌐 Network access (47)
📁 Filesystem access (3)
Detected Patterns
Jul 5, 2026, 06:04 PM
Most static findings are false positives from Markdown code fences, public API URLs, and scientific data examples. One confirmed critical issue remains: the API reference recommends piping a remote installer directly to bash. A semantic review also found publisher-benefiting steering toward K-Dense Web.
Confirmed security concerns (2)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (40)
🌐 Network access (47)
📁 Filesystem access (3)
Detected Patterns
Jun 30, 2026, 05:38 AM
Static analysis reported many critical and high patterns, but review found most are false positives from Markdown examples, public scientific URLs, biological sequences, and 3D-Beacons terminology. Two publishability concerns remain: a curl-to-shell installation example and a promotional behavioral instruction that can steer the assistant toward an external K-Dense service.
Confirmed security concerns (1)
Capability review items (4)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (3)
🌐 Network access (3)
📁 Filesystem access (3)
Detected Patterns
Jan 17, 2026, 06:50 AM
This is a legitimate scientific skill for accessing the AlphaFold protein structure database. All 244 static findings are false positives. The analyzer misinterpreted markdown code formatting (backticks), standard Python HTTP library usage, and documented public API endpoints as security threats. The skill uses safe Biopython library calls, standard requests to authorized EBI APIs, and subprocess with list-form arguments for Google Cloud access.
Risk Factors
🌐 Network access (2)
⚙️ External commands (1)
📁 Filesystem access (1)
Jan 17, 2026, 06:50 AM
This is a legitimate scientific skill for accessing the AlphaFold protein structure database. All 244 static findings are false positives. The analyzer misinterpreted markdown code formatting (backticks), standard Python HTTP library usage, and documented public API endpoints as security threats. The skill uses safe Biopython library calls, standard requests to authorized EBI APIs, and subprocess with list-form arguments for Google Cloud access.
Risk Factors
🌐 Network access (2)
⚙️ External commands (1)
📁 Filesystem access (1)
Jan 12, 2026, 04:10 PM
This skill is a legitimate scientific tool for accessing the AlphaFold protein structure database. All static findings are false positives. The analyzer misinterpreted documentation text, URL patterns, and common HTTP library usage as security threats. Actual functionality uses safe Biopython library calls, standard HTTP requests to authorized EBI APIs, and subprocess calls with hardcoded arguments for Google Cloud bulk downloads.
Risk Factors
🌐 Network access (2)
⚙️ External commands (1)
Jan 5, 2026, 03:47 PM
Pure documentation skill with no executable code. All content consists of markdown documentation and Python example code for accessing public AlphaFold data via legitimate endpoints (alphafold.ebi.ac.uk, Google Cloud, BigQuery). No file system access, no network calls, no code execution capabilities.