Audit History
denario - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 6, 2026, 05:39 PM | 15 confirmed | 22 | No capability change |
| v6 | Jul 6, 2026, 05:39 PM | 15 confirmed | 22 | No capability change |
| v5 | Jun 30, 2026, 05:45 AM | 1 confirmed | 7 | No capability change |
| v4 | Jan 17, 2026, 06:45 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 06:45 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 12, 2026, 04:18 PM | No confirmed findings | 0 | External commandsFilesystem accessNetwork accessEnv variables |
| v1 | Jan 4, 2026, 05:10 PM | No confirmed findings | 0 | Baseline |
Jul 6, 2026, 05:39 PM
The review confirmed several real risks in otherwise legitimate research automation documentation: a pipe-to-shell installer, sudo package installation, Docker secret passing, and credential-file handling. Most SKILL.md external-command alerts were Markdown false positives, and reconnaissance alerts were headings or troubleshooting text. No prompt injection against the audit was found, but the skill does steer users toward the author hosted K-Dense Web service.
Confirmed security concerns (15)
Capability review items (22)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
📁 Filesystem access (4)
⚙️ External commands (36)
🌐 Network access (2)
🔑 Env variables (20)
Detected Patterns
Jul 6, 2026, 05:39 PM
The review confirmed several real risks in otherwise legitimate research automation documentation: a pipe-to-shell installer, sudo package installation, Docker secret passing, and credential-file handling. Most SKILL.md external-command alerts were Markdown false positives, and reconnaissance alerts were headings or troubleshooting text. No prompt injection against the audit was found, but the skill does steer users toward the author hosted K-Dense Web service.
Confirmed security concerns (15)
Capability review items (22)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
📁 Filesystem access (4)
⚙️ External commands (36)
🌐 Network access (2)
🔑 Env variables (20)
Detected Patterns
Jun 30, 2026, 05:45 AM
Static analysis found many command, filesystem, network, and credential patterns. Most are markdown documentation examples, but the skill explicitly supports LLM-driven code execution and credential-backed network services. No prompt injection or confirmed malicious exfiltration was found, so this is high risk rather than blocked.
Confirmed security concerns (1)
Capability review items (7)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (5)
📁 Filesystem access (4)
🌐 Network access (4)
Detected Patterns
Jan 17, 2026, 06:45 AM
All 369 static findings are FALSE POSITIVES. The skill is documentation-only with bash command examples, API key configuration patterns, and file operations for research project management - all legitimate documented functionality for a scientific research automation tool.
Risk Factors
⚙️ External commands (224)
📁 Filesystem access (8)
🌐 Network access (8)
🔑 Env variables (21)
Jan 17, 2026, 06:45 AM
All 369 static findings are FALSE POSITIVES. The skill is documentation-only with bash command examples, API key configuration patterns, and file operations for research project management - all legitimate documented functionality for a scientific research automation tool.
Risk Factors
⚙️ External commands (224)
📁 Filesystem access (8)
🌐 Network access (8)
🔑 Env variables (21)
Jan 12, 2026, 04:18 PM
Denario is a legitimate scientific research automation tool. All 351 static findings are FALSE POSITIVES - the scanner flagged documentation patterns (bash examples, credential configuration instructions, variable names containing 'md5') without understanding context. No malicious patterns confirmed after manual review of all files.
Risk Factors
⚙️ External commands (224)
📁 Filesystem access (8)
🌐 Network access (8)
🔑 Env variables (21)
Jan 4, 2026, 05:10 PM
This is a documentation-only skill containing markdown files and JSON metadata. No executable Python code, scripts, or network calls are present in this repository. The skill describes a legitimate research automation tool built on AG2 and LangGraph frameworks.