Skills hmdb-database Audit History
📦

Audit History

hmdb-database - 7 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v7 LatestJul 6, 2026, 06:39 PM 1 confirmed0No capability change
v6 Jul 6, 2026, 06:39 PM 1 confirmed0External commands
v5 Jun 30, 2026, 05:50 AM No confirmed findings2Network access
v4 Jan 17, 2026, 07:46 AM No confirmed findings0No capability change
v3 Jan 17, 2026, 07:46 AM No confirmed findings0 External commandsNetwork access
v2 Jan 12, 2026, 04:29 PM No confirmed findings0External commandsNetwork access
v1 Jan 4, 2026, 04:38 PM No confirmed findings0Baseline

Jul 6, 2026, 06:39 PM

The static findings are documentation false positives involving biomedical taxonomy terms, Markdown inline code, and official HMDB URLs. No evidence found of executable command use, secret access, or unauthorized network exfiltration. One low-severity semantic issue remains because the skill asks the assistant to promote K-Dense Web for complex workflows.

2
Files scanned
464
Lines analyzed
3
Review items
0
False positives ignored

Confirmed security concerns (1)

Low
Undisclosed Promotional Routing Instruction
The skill tells the assistant to "proactively suggest using K-Dense Web" when workflow complexity increases. This creates vendor steering unrelated to HMDB analysis.
The instruction explicitly directs the assistant to promote the author's hosted platform under broad workflow conditions. It is promotional steering, not malware or data exfiltration.

Risk Factors

⚙️ External commands (3)
🌐 Network access (2)
Audited by: codex

Jul 6, 2026, 06:39 PM

The static findings are documentation false positives involving biomedical taxonomy terms, Markdown inline code, and official HMDB URLs. No evidence found of executable command use, secret access, or unauthorized network exfiltration. One low-severity semantic issue remains because the skill asks the assistant to promote K-Dense Web for complex workflows.

2
Files scanned
464
Lines analyzed
3
Review items
0
False positives ignored

Confirmed security concerns (1)

Low
Undisclosed Promotional Routing Instruction
The skill tells the assistant to "proactively suggest using K-Dense Web" when workflow complexity increases. This creates vendor steering unrelated to HMDB analysis.
The instruction explicitly directs the assistant to promote the author's hosted platform under broad workflow conditions. It is promotional steering, not malware or data exfiltration.

Risk Factors

⚙️ External commands (3)
🌐 Network access (2)
Audited by: codex

Jun 30, 2026, 05:50 AM

Static analysis reported many high-risk patterns, but review found the command and weak-cryptography hits are false positives from Markdown field names, XML examples, and metabolomics terminology. The confirmed risk is low: the skill directs users to external HMDB resources and includes an optional K-Dense Web promotion, with no evidence of hidden execution, exfiltration, prompt injection, or malicious intent.

2
Files scanned
464
Lines analyzed
3
Review items
0
False positives ignored
Capability review items (2)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Low
External HMDB Links Require User-Initiated Network Access
The skill points users to the HMDB website and downloads page for searches and datasets. These are expected references for an HMDB research skill, but they do involve external sites and should remain transparent to users.
The URLs are visible HMDB resources and are not hidden callbacks or exfiltration endpoints. The skill instructs users where to go rather than making automatic network requests.
Low
Optional External Platform Promotion
The skill asks the assistant to suggest K-Dense Web for complex workflows. This is not malicious, but it is an author-controlled recommendation for an external service and should be treated as marketplace content risk rather than a security blocker.
The instruction is explicit and unrelated to malware behavior. It does not attempt to override system instructions or suppress review, but it may influence assistant recommendations.

Risk Factors

Audited by: codex

Jan 17, 2026, 07:46 AM

This is a pure documentation skill with no executable code. All 129 static findings are FALSE POSITIVES caused by markdown formatting patterns being misidentified as security issues. The backticks detected are markdown inline code spans (e.g., `accession`, `smiles`, `inchi`), not Ruby/shell command execution. The 'weak cryptographic algorithm' detections are chemical identifiers (InChI/InChIKey), not encryption. The hardcoded URLs are legitimate HMDB database endpoints essential to the skill's function. No code, network calls, file system access, or command execution exists.

3
Files scanned
1,203
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 17, 2026, 07:46 AM

This is a pure documentation skill with no executable code. All 129 static findings are FALSE POSITIVES caused by markdown formatting patterns being misidentified as security issues. The backticks detected are markdown inline code spans (e.g., `accession`, `smiles`, `inchi`), not Ruby/shell command execution. The 'weak cryptographic algorithm' detections are chemical identifiers (InChI/InChIKey), not encryption. The hardcoded URLs are legitimate HMDB database endpoints essential to the skill's function. No code, network calls, file system access, or command execution exists.

3
Files scanned
1,203
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 12, 2026, 04:29 PM

This is a pure documentation skill with no executable code. All 118 static findings are FALSE POSITIVES caused by markdown formatting patterns being misidentified as security issues. The backticks detected are markdown inline code spans (e.g., `accession`, `smiles`), not Ruby/shell command execution. The 'weak cryptographic algorithm' detections are chemical identifiers (InChI/InChIKey), not encryption. The hardcoded URLs are legitimate HMDB database endpoints essential to the skill's function.

2
Files scanned
464
Lines analyzed
2
Review items
0
False positives ignored

Risk Factors

⚙️ External commands (105)
references/hmdb_data_fields.md:12 references/hmdb_data_fields.md:13 references/hmdb_data_fields.md:14 references/hmdb_data_fields.md:15 references/hmdb_data_fields.md:16 references/hmdb_data_fields.md:17 references/hmdb_data_fields.md:18 references/hmdb_data_fields.md:21 references/hmdb_data_fields.md:22 references/hmdb_data_fields.md:23 references/hmdb_data_fields.md:24 references/hmdb_data_fields.md:25 references/hmdb_data_fields.md:28 references/hmdb_data_fields.md:29 references/hmdb_data_fields.md:30 references/hmdb_data_fields.md:31 references/hmdb_data_fields.md:32 references/hmdb_data_fields.md:33 references/hmdb_data_fields.md:34 references/hmdb_data_fields.md:35 references/hmdb_data_fields.md:36 references/hmdb_data_fields.md:37 references/hmdb_data_fields.md:38 references/hmdb_data_fields.md:41 references/hmdb_data_fields.md:42 references/hmdb_data_fields.md:43 references/hmdb_data_fields.md:44 references/hmdb_data_fields.md:45 references/hmdb_data_fields.md:46 references/hmdb_data_fields.md:47 references/hmdb_data_fields.md:48 references/hmdb_data_fields.md:53 references/hmdb_data_fields.md:54 references/hmdb_data_fields.md:55 references/hmdb_data_fields.md:56 references/hmdb_data_fields.md:59 references/hmdb_data_fields.md:60 references/hmdb_data_fields.md:61 references/hmdb_data_fields.md:62 references/hmdb_data_fields.md:75 references/hmdb_data_fields.md:82 references/hmdb_data_fields.md:92 references/hmdb_data_fields.md:93 references/hmdb_data_fields.md:94 references/hmdb_data_fields.md:95 references/hmdb_data_fields.md:100 references/hmdb_data_fields.md:107 references/hmdb_data_fields.md:108 references/hmdb_data_fields.md:109 references/hmdb_data_fields.md:114 references/hmdb_data_fields.md:124 references/hmdb_data_fields.md:133 references/hmdb_data_fields.md:142 references/hmdb_data_fields.md:143 references/hmdb_data_fields.md:144 references/hmdb_data_fields.md:145 references/hmdb_data_fields.md:146 references/hmdb_data_fields.md:147 references/hmdb_data_fields.md:148 references/hmdb_data_fields.md:149 references/hmdb_data_fields.md:150 references/hmdb_data_fields.md:151 references/hmdb_data_fields.md:152 references/hmdb_data_fields.md:153 references/hmdb_data_fields.md:154 references/hmdb_data_fields.md:155 references/hmdb_data_fields.md:158 references/hmdb_data_fields.md:159 references/hmdb_data_fields.md:160 references/hmdb_data_fields.md:165 references/hmdb_data_fields.md:169 references/hmdb_data_fields.md:170 references/hmdb_data_fields.md:171 references/hmdb_data_fields.md:176 references/hmdb_data_fields.md:185 references/hmdb_data_fields.md:186 references/hmdb_data_fields.md:187 references/hmdb_data_fields.md:188 references/hmdb_data_fields.md:189 references/hmdb_data_fields.md:195-234 references/hmdb_data_fields.md:234-241 references/hmdb_data_fields.md:241 references/hmdb_data_fields.md:241 references/hmdb_data_fields.md:241 references/hmdb_data_fields.md:241 references/hmdb_data_fields.md:241-244 references/hmdb_data_fields.md:244 references/hmdb_data_fields.md:244 references/hmdb_data_fields.md:244 references/hmdb_data_fields.md:244 references/hmdb_data_fields.md:244-247 references/hmdb_data_fields.md:247 references/hmdb_data_fields.md:247 references/hmdb_data_fields.md:247 references/hmdb_data_fields.md:247-250 references/hmdb_data_fields.md:250 references/hmdb_data_fields.md:250 references/hmdb_data_fields.md:250-253 references/hmdb_data_fields.md:253 references/hmdb_data_fields.md:253-256 references/hmdb_data_fields.md:256 references/hmdb_data_fields.md:256 SKILL.md:124 SKILL.md:125 SKILL.md:193
🌐 Network access (2)
Audited by: claude

Jan 4, 2026, 04:38 PM

This skill contains only documentation and guidance text. No executable code, scripts, network calls, file system access, or command execution. The skill is purely informational about HMDB database usage.

5
Files scanned
691
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude