Audit History
hmdb-database - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 6, 2026, 06:39 PM | 1 confirmed | 0 | No capability change |
| v6 | Jul 6, 2026, 06:39 PM | 1 confirmed | 0 | External commands |
| v5 | Jun 30, 2026, 05:50 AM | No confirmed findings | 2 | Network access |
| v4 | Jan 17, 2026, 07:46 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 07:46 AM | No confirmed findings | 0 | External commandsNetwork access |
| v2 | Jan 12, 2026, 04:29 PM | No confirmed findings | 0 | External commandsNetwork access |
| v1 | Jan 4, 2026, 04:38 PM | No confirmed findings | 0 | Baseline |
Jul 6, 2026, 06:39 PM
The static findings are documentation false positives involving biomedical taxonomy terms, Markdown inline code, and official HMDB URLs. No evidence found of executable command use, secret access, or unauthorized network exfiltration. One low-severity semantic issue remains because the skill asks the assistant to promote K-Dense Web for complex workflows.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (3)
🌐 Network access (2)
Jul 6, 2026, 06:39 PM
The static findings are documentation false positives involving biomedical taxonomy terms, Markdown inline code, and official HMDB URLs. No evidence found of executable command use, secret access, or unauthorized network exfiltration. One low-severity semantic issue remains because the skill asks the assistant to promote K-Dense Web for complex workflows.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (3)
🌐 Network access (2)
Jun 30, 2026, 05:50 AM
Static analysis reported many high-risk patterns, but review found the command and weak-cryptography hits are false positives from Markdown field names, XML examples, and metabolomics terminology. The confirmed risk is low: the skill directs users to external HMDB resources and includes an optional K-Dense Web promotion, with no evidence of hidden execution, exfiltration, prompt injection, or malicious intent.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🌐 Network access (3)
Jan 17, 2026, 07:46 AM
This is a pure documentation skill with no executable code. All 129 static findings are FALSE POSITIVES caused by markdown formatting patterns being misidentified as security issues. The backticks detected are markdown inline code spans (e.g., `accession`, `smiles`, `inchi`), not Ruby/shell command execution. The 'weak cryptographic algorithm' detections are chemical identifiers (InChI/InChIKey), not encryption. The hardcoded URLs are legitimate HMDB database endpoints essential to the skill's function. No code, network calls, file system access, or command execution exists.
Jan 17, 2026, 07:46 AM
This is a pure documentation skill with no executable code. All 129 static findings are FALSE POSITIVES caused by markdown formatting patterns being misidentified as security issues. The backticks detected are markdown inline code spans (e.g., `accession`, `smiles`, `inchi`), not Ruby/shell command execution. The 'weak cryptographic algorithm' detections are chemical identifiers (InChI/InChIKey), not encryption. The hardcoded URLs are legitimate HMDB database endpoints essential to the skill's function. No code, network calls, file system access, or command execution exists.
Jan 12, 2026, 04:29 PM
This is a pure documentation skill with no executable code. All 118 static findings are FALSE POSITIVES caused by markdown formatting patterns being misidentified as security issues. The backticks detected are markdown inline code spans (e.g., `accession`, `smiles`), not Ruby/shell command execution. The 'weak cryptographic algorithm' detections are chemical identifiers (InChI/InChIKey), not encryption. The hardcoded URLs are legitimate HMDB database endpoints essential to the skill's function.
Risk Factors
⚙️ External commands (105)
🌐 Network access (2)
Jan 4, 2026, 04:38 PM
This skill contains only documentation and guidance text. No executable code, scripts, network calls, file system access, or command execution. The skill is purely informational about HMDB database usage.