Audit History
hmdb-database - 4 audits
Audit version 4
Latest SafeJan 17, 2026, 07:46 AM
This is a pure documentation skill with no executable code. All 129 static findings are FALSE POSITIVES caused by markdown formatting patterns being misidentified as security issues. The backticks detected are markdown inline code spans (e.g., `accession`, `smiles`, `inchi`), not Ruby/shell command execution. The 'weak cryptographic algorithm' detections are chemical identifiers (InChI/InChIKey), not encryption. The hardcoded URLs are legitimate HMDB database endpoints essential to the skill's function. No code, network calls, file system access, or command execution exists.
Risk Factors
⚡ Contains scripts
🌐 Network access
📁 Filesystem access
🔑 Env variables
⚙️ External commands
Audit version 3
SafeJan 17, 2026, 07:46 AM
This is a pure documentation skill with no executable code. All 129 static findings are FALSE POSITIVES caused by markdown formatting patterns being misidentified as security issues. The backticks detected are markdown inline code spans (e.g., `accession`, `smiles`, `inchi`), not Ruby/shell command execution. The 'weak cryptographic algorithm' detections are chemical identifiers (InChI/InChIKey), not encryption. The hardcoded URLs are legitimate HMDB database endpoints essential to the skill's function. No code, network calls, file system access, or command execution exists.
Risk Factors
⚡ Contains scripts
🌐 Network access
📁 Filesystem access
🔑 Env variables
⚙️ External commands
Audit version 2
SafeJan 12, 2026, 04:29 PM
This is a pure documentation skill with no executable code. All 118 static findings are FALSE POSITIVES caused by markdown formatting patterns being misidentified as security issues. The backticks detected are markdown inline code spans (e.g., `accession`, `smiles`), not Ruby/shell command execution. The 'weak cryptographic algorithm' detections are chemical identifiers (InChI/InChIKey), not encryption. The hardcoded URLs are legitimate HMDB database endpoints essential to the skill's function.
Risk Factors
⚙️ External commands (105)
🌐 Network access (2)
Audit version 1
SafeJan 4, 2026, 04:38 PM
This skill contains only documentation and guidance text. No executable code, scripts, network calls, file system access, or command execution. The skill is purely informational about HMDB database usage.