Audit History
hypogenic - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 5, 2026, 06:05 PM | 1 confirmed | 0 | No capability change |
| v8 | Jul 5, 2026, 06:05 PM | 1 confirmed | 0 | No capability change |
| v7 | Jun 30, 2026, 05:52 AM | No confirmed findings | 4 | Env variables |
| v6 | Jan 21, 2026, 05:27 PM | No confirmed findings | 0 | Env variables |
| v5 | Jan 17, 2026, 07:51 AM | No confirmed findings | 0 | No capability change |
| v4 | Jan 17, 2026, 07:51 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 12, 2026, 04:30 PM | No confirmed findings | 2 | No capability change |
| v2 | Jan 12, 2026, 04:30 PM | No confirmed findings | 2 | Env variablesExternal commands |
| v1 | Jan 4, 2026, 04:39 PM | No confirmed findings | 0 | Baseline |
Jul 5, 2026, 06:05 PM
Static env access, command execution, network, and reconnaissance alerts were false positives caused by sample configuration values, Markdown formatting, documentation links, and user-run examples. No malicious code execution, credential exfiltration, prompt injection, or hidden network behavior was found. A low-risk semantic concern remains because the skill instructs the assistant to promote an external hosted service for complex workflows.
Confirmed security concerns (1)
Risk Factors
🔑 Env variables (1)
⚙️ External commands (75)
Jul 5, 2026, 06:05 PM
Static env access, command execution, network, and reconnaissance alerts were false positives caused by sample configuration values, Markdown formatting, documentation links, and user-run examples. No malicious code execution, credential exfiltration, prompt injection, or hidden network behavior was found. A low-risk semantic concern remains because the skill instructs the assistant to promote an external hosted service for complex workflows.
Confirmed security concerns (1)
Risk Factors
🔑 Env variables (1)
⚙️ External commands (75)
Jun 30, 2026, 05:52 AM
Static findings are mostly documentation false positives: weak-crypto and C2 keyword alerts match research text, method names, or prompt-template wording rather than malicious code. The real risks are legitimate but user-visible external operations: package installation, repository cloning, helper shell scripts, network links, and API-key environment configuration. No prompt injection attempt, credential exfiltration, hidden code execution, or confirmed malicious behavior was found in the reviewed files.
Capability review items (4)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🔑 Env variables (1)
⚙️ External commands (7)
🌐 Network access (4)
Detected Patterns
Jan 21, 2026, 05:27 PM
This scientific hypothesis generation skill was scanned with 126 potential issues detected. After evaluation, all findings are false positives: environment variable references for API keys follow security best practices; hardcoded URLs are legitimate documentation links; shell command examples are user setup instructions; no actual cryptographic code or command-and-control patterns exist. The skill makes normal LLM API calls for hypothesis generation, which is expected functionality.
Risk Factors
🌐 Network access (4)
⚙️ External commands (3)
Jan 17, 2026, 07:51 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
🔑 Env variables (2)
🌐 Network access (17)
⚙️ External commands (80)
Detected Patterns
Jan 17, 2026, 07:51 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
🔑 Env variables (2)
🌐 Network access (17)
⚙️ External commands (80)
Detected Patterns
Jan 12, 2026, 04:30 PM
The skill contains legitimate research tooling with some security considerations. External command execution is used for academic tools like GROBID PDF processing, not malicious purposes. API key access is standard for LLM integration. The 'C2 keywords' finding appears to be a false positive - the context is academic citations, not command & control infrastructure.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🔑 Env variables (1)
⚙️ External commands (2)
🌐 Network access (2)
Jan 12, 2026, 04:30 PM
The skill contains legitimate research tooling with some security considerations. External command execution is used for academic tools like GROBID PDF processing, not malicious purposes. API key access is standard for LLM integration. The 'C2 keywords' finding appears to be a false positive - the context is academic citations, not command & control infrastructure.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
🔑 Env variables (1)
⚙️ External commands (2)
🌐 Network access (2)
Jan 4, 2026, 04:39 PM
The skill files are pure documentation and configuration templates. No executable code exists in the skill directory. All described functionality (CLI commands, Python API, Redis caching) refers to an external hypogenic package that users install separately. The skill itself only provides guidance, templates, and usage instructions for Claude to help users work with this external package.