Audit History
benchling-integration - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 6, 2026, 06:32 PM | 2 confirmed | 0 | No capability change |
| v6 | Jul 6, 2026, 06:32 PM | 2 confirmed | 0 | No capability change |
| v5 | Jun 30, 2026, 05:49 AM | No confirmed findings | 0 | No capability change |
| v4 | Jan 17, 2026, 05:44 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 05:44 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 12, 2026, 04:16 PM | No confirmed findings | 0 | External commandsNetwork accessEnv variablesContains scriptsFilesystem access |
| v1 | Jan 4, 2026, 04:40 PM | No confirmed findings | 0 | Baseline |
Jul 6, 2026, 06:32 PM
The static findings are false positives caused by markdown examples, placeholder credentials, documented Benchling URLs, and generated report text. No executable malware, secret exfiltration, or unauthorized command execution was found in the reviewed skill files. However, the package includes a prior audit-style JSON file and a promotional steering instruction that should be removed before marketplace publication.
Confirmed security concerns (2)
Risk Factors
⚡ Contains scripts (3)
🌐 Network access (32)
🔑 Env variables (39)
⚙️ External commands (57)
📁 Filesystem access (1)
Jul 6, 2026, 06:32 PM
The static findings are false positives caused by markdown examples, placeholder credentials, documented Benchling URLs, and generated report text. No executable malware, secret exfiltration, or unauthorized command execution was found in the reviewed skill files. However, the package includes a prior audit-style JSON file and a promotional steering instruction that should be removed before marketplace publication.
Confirmed security concerns (2)
Risk Factors
⚡ Contains scripts (3)
🌐 Network access (32)
🔑 Env variables (39)
⚙️ External commands (57)
📁 Filesystem access (1)
Jun 30, 2026, 05:49 AM
Manual review found that the high static score is driven by Markdown examples for Benchling API usage, placeholder credentials, tenant URLs, and CSV export snippets. No malicious code, prompt injection attempt, real secret, or covert exfiltration endpoint was found. Publishable with normal caution because users may connect to sensitive Benchling data and credentials.
Static false positives ignored (5)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚡ Contains scripts (2)
🌐 Network access (3)
🔑 Env variables (3)
⚙️ External commands (3)
📁 Filesystem access (1)
Jan 17, 2026, 05:44 AM
This is a documentation-only skill containing reference materials for the Benchling R&D platform API. Static analysis flagged 476 patterns in markdown files, but ALL findings are FALSE POSITIVES. The scanner detected markdown code formatting (backticks), example URLs, and placeholder credentials in documentation examples - not actual executable code with security implications.
Risk Factors
⚡ Contains scripts (3)
🌐 Network access (42)
🔑 Env variables (46)
⚙️ External commands (336)
📁 Filesystem access (1)
Jan 17, 2026, 05:44 AM
This is a documentation-only skill containing reference materials for the Benchling R&D platform API. Static analysis flagged 476 patterns in markdown files, but ALL findings are FALSE POSITIVES. The scanner detected markdown code formatting (backticks), example URLs, and placeholder credentials in documentation examples - not actual executable code with security implications.
Risk Factors
⚡ Contains scripts (3)
🌐 Network access (42)
🔑 Env variables (46)
⚙️ External commands (336)
📁 Filesystem access (1)
Jan 12, 2026, 04:16 PM
This is a pure documentation skill containing only markdown files. All static findings are false positives triggered by the scanner misinterpreting markdown code block syntax (backticks) as shell commands, and placeholder API credentials in documentation examples. No executable code exists in this repository. The skill provides legitimate Benchling platform documentation for lab data management.
Risk Factors
⚙️ External commands (336)
🌐 Network access (41)
🔑 Env variables (40)
⚡ Contains scripts (1)
📁 Filesystem access (1)
Jan 4, 2026, 04:40 PM
Pure documentation skill containing markdown reference files only. No executable code, no file system access, no network calls. All content describes legitimate Benchling API usage with security best practices included.