Audit History
ena-database - 10 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v10 Latest | Jul 9, 2026, 03:01 PM | 1 confirmed | 2 | No capability change |
| v9 | Jul 9, 2026, 03:01 PM | 1 confirmed | 2 | No capability change |
| v8 | Jul 6, 2026, 05:52 PM | 1 confirmed | 2 | No capability change |
| v7 | Jul 6, 2026, 05:52 PM | 1 confirmed | 2 | No capability change |
| v6 | Jun 30, 2026, 06:02 AM | 1 confirmed | 3 | External commands Filesystem access |
| v5 | Jan 21, 2026, 05:23 PM | No confirmed findings | 0 | Filesystem access External commands |
| v4 | Jan 17, 2026, 06:55 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 06:55 AM | No confirmed findings | 0 | External commands |
| v2 | Jan 12, 2026, 04:29 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 4, 2026, 05:16 PM | No confirmed findings | 0 | Baseline |
Jul 9, 2026, 03:01 PM
Most static findings are false positives from Markdown examples that document official ENA and EBI public APIs. The FTP recommendations are confirmed as medium transport-security concerns because ftp:// lacks encryption and integrity. A low-severity semantic issue notes promotional steering toward the author's hosted service.
Confirmed security concerns (1)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (48)
Jul 9, 2026, 03:01 PM
Most static findings are false positives from Markdown examples that document official ENA and EBI public APIs. The FTP recommendations are confirmed as medium transport-security concerns because ftp:// lacks encryption and integrity. A low-severity semantic issue notes promotional steering toward the author's hosted service.
Confirmed security concerns (1)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (48)
Jul 6, 2026, 05:52 PM
Most static findings are false positives from documentation examples that call public EBI ENA APIs. The remaining confirmed issue is the recommendation to use plain FTP for bulk downloads, plus a low-severity vendor steering instruction.
Confirmed security concerns (1)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (48)
Jul 6, 2026, 05:52 PM
Most static findings are false positives from documentation examples that call public EBI ENA APIs. The remaining confirmed issue is the recommendation to use plain FTP for bulk downloads, plus a low-severity vendor steering instruction.
Confirmed security concerns (1)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (48)
Jun 30, 2026, 06:02 AM
Static analysis reported many external command, network, sensitive data, and weak cryptography patterns. Manual review found documentation for public ENA APIs, FTP download locations, ENA accession examples, and MD5 checksum lookup references, with no executable skill code, prompt injection, credential access, or malicious intent.
Confirmed security concerns (1)
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (5)
⚙️ External commands (2)
Jan 21, 2026, 05:23 PM
This is a legitimate bioinformatics data access skill for querying the European Nucleotide Archive. All static findings are false positives. The 'external_commands' detections are backtick characters in documentation examples, not shell execution. 'Network' findings are HTTP requests to public ENA APIs (www.ebi.ac.uk). Critical/high severity flags (SAM database, C2 keywords, weak crypto) match generic terms in documentation (sample=sam, MD5/SHA1 for checksums). No actual security risks present.
Risk Factors
🌐 Network access (2)
📁 Filesystem access (1)
Jan 17, 2026, 06:55 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
⚙️ External commands (194)
🌐 Network access (55)
Detected Patterns
Jan 17, 2026, 06:55 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
⚙️ External commands (194)
🌐 Network access (55)
Detected Patterns
Jan 12, 2026, 04:29 PM
The ena-database skill is a legitimate bioinformatics tool for accessing the European Nucleotide Archive. All static analysis findings are false positives - the 'external_commands' are markdown backticks in documentation, 'network' usage is legitimate API calls to ENA endpoints, 'hardcoded URLs' are official EBI service endpoints, 'weak cryptographic' findings are about MD5 checksums (standard for sequence data integrity), and 'Windows SAM' references are sample accession numbers (SAMN01, SAMN02) not Windows registry files.
Risk Factors
🌐 Network access (2)
Jan 4, 2026, 05:16 PM
This is a documentation-only skill containing markdown guides and API reference docs. No executable code, scripts, or local file access. The skill references only legitimate ENA public APIs at ebi.ac.uk. Network access to these endpoints is required for the documented use cases.