Audit History
ena-database - 5 audits
Audit version 5
Latest Low RiskJan 21, 2026, 05:23 PM
This is a legitimate bioinformatics data access skill for querying the European Nucleotide Archive. All static findings are false positives. The 'external_commands' detections are backtick characters in documentation examples, not shell execution. 'Network' findings are HTTP requests to public ENA APIs (www.ebi.ac.uk). Critical/high severity flags (SAM database, C2 keywords, weak crypto) match generic terms in documentation (sample=sam, MD5/SHA1 for checksums). No actual security risks present.
Risk Factors
🌐 Network access (2)
📁 Filesystem access (1)
Audit version 4
Medium RiskJan 17, 2026, 06:55 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
⚙️ External commands (194)
🌐 Network access (56)
Detected Patterns
Audit version 3
Medium RiskJan 17, 2026, 06:55 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
⚙️ External commands (194)
🌐 Network access (56)
Detected Patterns
Audit version 2
SafeJan 12, 2026, 04:29 PM
The ena-database skill is a legitimate bioinformatics tool for accessing the European Nucleotide Archive. All static analysis findings are false positives - the 'external_commands' are markdown backticks in documentation, 'network' usage is legitimate API calls to ENA endpoints, 'hardcoded URLs' are official EBI service endpoints, 'weak cryptographic' findings are about MD5 checksums (standard for sequence data integrity), and 'Windows SAM' references are sample accession numbers (SAMN01, SAMN02) not Windows registry files.
Risk Factors
🌐 Network access (2)
Audit version 1
Low RiskJan 4, 2026, 05:16 PM
This is a documentation-only skill containing markdown guides and API reference docs. No executable code, scripts, or local file access. The skill references only legitimate ENA public APIs at ebi.ac.uk. Network access to these endpoints is required for the documented use cases.