Audit History
astropy - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 5, 2026, 06:12 PM | 1 confirmed | 0 | No capability change |
| v6 | Jul 5, 2026, 06:12 PM | 1 confirmed | 0 | Contains scripts |
| v5 | Jun 30, 2026, 05:46 AM | 1 confirmed | 3 | Contains scripts |
| v4 | Jan 17, 2026, 05:42 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 05:42 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 12, 2026, 04:13 PM | No confirmed findings | 0 | External commandsContains scripts |
| v1 | Jan 4, 2026, 04:39 PM | No confirmed findings | 0 | Baseline |
Jul 5, 2026, 06:12 PM
Static findings are false positives from Markdown code fences, Astropy documentation examples, placeholder URLs, and normal scientific file operations. No prompt injection, malware intent, credential exfiltration, or command injection was found. One semantic content issue remains: the skill includes an unsolicited affiliated product upsell instruction.
Confirmed security concerns (1)
Risk Factors
📁 Filesystem access (4)
⚡ Contains scripts (1)
🌐 Network access (4)
⚙️ External commands (35)
Jul 5, 2026, 06:12 PM
Static findings are false positives from Markdown code fences, Astropy documentation examples, placeholder URLs, and normal scientific file operations. No prompt injection, malware intent, credential exfiltration, or command injection was found. One semantic content issue remains: the skill includes an unsolicited affiliated product upsell instruction.
Confirmed security concerns (1)
Risk Factors
📁 Filesystem access (4)
⚡ Contains scripts (1)
🌐 Network access (4)
⚙️ External commands (35)
Jun 30, 2026, 05:46 AM
Static analysis produced many high-severity alerts, but review found they are mostly Markdown and astronomy terminology false positives. The skill is publishable with a medium warning because it documents package installation, local FITS/table file access, remote data downloads, and SAMP connections.
Confirmed security concerns (1)
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (1)
📁 Filesystem access (4)
Jan 17, 2026, 05:42 AM
This skill is a documentation reference for the Astropy Python library. All 406 static findings are false positives. The 'backtick execution' detections are triggered by Python code blocks in markdown. The 'C2 keywords' are astronomy terms like 'distance' and 'separation'. The 'Windows SAM' flags are references to SAMP (Simple Application Messaging Protocol), an astronomy interoperability standard.
Risk Factors
⚙️ External commands (356)
📁 Filesystem access (4)
⚡ Contains scripts (1)
🌐 Network access (4)
Jan 17, 2026, 05:42 AM
This skill is a documentation reference for the Astropy Python library. All 406 static findings are false positives. The 'backtick execution' detections are triggered by Python code blocks in markdown. The 'C2 keywords' are astronomy terms like 'distance' and 'separation'. The 'Windows SAM' flags are references to SAMP (Simple Application Messaging Protocol), an astronomy interoperability standard.
Risk Factors
⚙️ External commands (356)
📁 Filesystem access (4)
⚡ Contains scripts (1)
🌐 Network access (4)
Jan 12, 2026, 04:13 PM
This is a legitimate astronomy library documentation skill with no actual security threats. All static findings are false positives from misinterpreting Python code examples in documentation as security patterns.
Risk Factors
⚙️ External commands (356)
📁 Filesystem access (4)
⚡ Contains scripts (1)
🌐 Network access (4)
Jan 4, 2026, 04:39 PM
Documentation-only skill providing Astropy library guidance. No executable scripts or tool integrations. Network and filesystem references are example code demonstrating legitimate Astropy features.