Versioned security assessment

Report ID: SA-EC4BCFB8

6/30/2026, 5:49:31 AM

benchling-integration security assessment v5

Skill Security Certification Report

Audit History
Audit model: codex Historical report
Skill name
benchling-integration
Version
v5
Maintainer
K-Dense-AI
Coverage
5 Files scanned · 2,736 Lines analyzed
Policy version
Unavailable

Confirmed finding summary

No confirmed security findings

The completed audit recorded no confirmed security findings. This is not proof that the Skill has no side effects.

Installation context

Historical evidence

This report may not describe the currently installable artifact. Open the current Skill page for install guidance.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

Manual review found that the high static score is driven by Markdown examples for Benchling API usage, placeholder credentials, tenant URLs, and CSV export snippets. No malicious code, prompt injection attempt, real secret, or covert exfiltration endpoint was found. Publishable with normal caution because users may connect to sensitive Benchling data and credentials.

Report position

Historical report

Open audit history before using this report to install.

Audit attestation

Not attestable

The required immutable binding is incomplete.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

5 Files scanned · 2,736 Lines analyzed

0 items shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Binding unavailable

  2. Artifact

    Identity incomplete

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Observed in 2 evidence locations

Network access

May connect to external services.

Observed in 3 evidence locations

Filesystem access

May read or write local files.

Observed in 1 evidence location

Env variables

May read values from the process environment.

Observed in 3 evidence locations

External commands

May invoke commands or programs outside the Skill.

Observed in 3 evidence locations

Risk findings

Confirmed security concerns are separated from items that still need review.

No confirmed security findings were recorded for this completed audit.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
Unavailable
Content hash
Unavailable
Tree hash
Unavailable
Skill path
Unavailable
Audit payload hash
Unavailable

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Static false positives ignored (5)
Low
Static command execution alerts are Markdown examples
The numerous backtick execution alerts occur in Markdown documentation and code fences. I did not find evidence that the skill package executes shell, Ruby, or Python commands itself.
The cited locations are documentation snippets and Markdown formatting, not executable package code. This is a strong false-positive signal after reviewing the surrounding context.
Low
Placeholder credential and environment examples
The API key and environment variable alerts are instructional placeholders for Benchling authentication. They do not expose real secrets, but users must avoid copying real credentials into prompts or files.
The reviewed values are placeholders and security guidance, not embedded credentials. The remaining risk is operational because the skill teaches real credential-based integrations.
Low
Network findings match expected Benchling API documentation
Hardcoded URL and fetch alerts point to Benchling tenant URL examples and REST API reference material. I did not find evidence of covert endpoints or unauthorized data exfiltration.
The network locations are expected for an API integration skill and use Benchling documentation domains or tenant placeholders. No unrelated collection endpoint was found.
Low
Filesystem write example is documentation only
The file write alert comes from an example that exports sequence metadata to CSV. It is not executed by the skill, but copied scripts could write sensitive lab data locally.
The surrounding context is a documentation example, so the package does not perform a write operation. The caution is credible because Benchling data can be sensitive if users run adapted exports.
Low
Critical heuristic combination is not confirmed
The scanner combined documentation examples for commands, network calls, credential setup, and file export into a critical heuristic. Manual review did not find malicious intent, obfuscation, or prompt-injection instructions.
Multiple risky tokens are present, but they are explained by reference documentation for a legitimate API integration. I found no semantic evidence of exfiltration, hidden execution, or audit bypass text.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: not_attestable