📦

Audit History

iso-13485-certification - 9 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v9 LatestJul 9, 2026, 03:25 PM No confirmed findings0No capability change
v8 Jul 9, 2026, 03:25 PM No confirmed findings0No capability change
v7 Jul 5, 2026, 06:09 PM No confirmed findings1No capability change
v6 Jul 5, 2026, 06:09 PM No confirmed findings1Env variables Contains scripts
v5 Jun 30, 2026, 05:56 AM 2 confirmed0Contains scriptsExternal commands
v4 Jan 17, 2026, 07:53 AM No confirmed findings0No capability change
v3 Jan 17, 2026, 07:53 AM No confirmed findings0 Contains scripts
v2 Jan 12, 2026, 04:33 PM No confirmed findings0No capability change
v1 Jan 4, 2026, 04:41 PM No confirmed findings0Baseline

Jul 9, 2026, 03:25 PM

Manual review found the static alerts are false positives caused by ISO 13485 terminology, markdown file references, and an explicit local report writer. No prompt injection, hidden network access, credential access, or unauthorized command execution was found in the reviewed files.

9
Files scanned
5,141
Lines analyzed
3
Review items
0
False positives ignored

Risk Factors

🔑 Env variables (69)
assets/templates/procedures/CAPA-procedure-template.md:54 assets/templates/procedures/CAPA-procedure-template.md:55 assets/templates/procedures/CAPA-procedure-template.md:68 assets/templates/procedures/CAPA-procedure-template.md:69 assets/templates/procedures/CAPA-procedure-template.md:80 assets/templates/procedures/CAPA-procedure-template.md:81 assets/templates/procedures/CAPA-procedure-template.md:82 assets/templates/procedures/CAPA-procedure-template.md:124 assets/templates/procedures/CAPA-procedure-template.md:135 assets/templates/procedures/CAPA-procedure-template.md:137 assets/templates/procedures/CAPA-procedure-template.md:139 assets/templates/procedures/CAPA-procedure-template.md:143 assets/templates/procedures/CAPA-procedure-template.md:151 assets/templates/procedures/CAPA-procedure-template.md:153 assets/templates/procedures/CAPA-procedure-template.md:189 assets/templates/procedures/CAPA-procedure-template.md:427 assets/templates/procedures/document-control-procedure-template.md:421 assets/templates/quality-manual-template.md:88 assets/templates/quality-manual-template.md:151 assets/templates/quality-manual-template.md:337 references/gap-analysis-checklist.md:406 references/gap-analysis-checklist.md:410 references/gap-analysis-checklist.md:414 references/gap-analysis-checklist.md:415 references/gap-analysis-checklist.md:416 references/gap-analysis-checklist.md:421 references/gap-analysis-checklist.md:453 references/gap-analysis-checklist.md:454 references/gap-analysis-checklist.md:461 references/iso-13485-requirements.md:348 references/iso-13485-requirements.md:519 references/iso-13485-requirements.md:522 references/iso-13485-requirements.md:526 references/iso-13485-requirements.md:527 references/iso-13485-requirements.md:529 references/iso-13485-requirements.md:530 references/iso-13485-requirements.md:531 references/iso-13485-requirements.md:534 references/iso-13485-requirements.md:538 references/iso-13485-requirements.md:539 references/iso-13485-requirements.md:540 references/iso-13485-requirements.md:548 references/iso-13485-requirements.md:572 references/iso-13485-requirements.md:573 references/iso-13485-requirements.md:574 references/iso-13485-requirements.md:582 references/iso-13485-requirements.md:592 references/mandatory-documents.md:356 references/mandatory-documents.md:357 references/mandatory-documents.md:359 references/mandatory-documents.md:361 references/mandatory-documents.md:362 references/mandatory-documents.md:363 references/mandatory-documents.md:367 references/mandatory-documents.md:368 references/mandatory-documents.md:372 references/mandatory-documents.md:374 references/mandatory-documents.md:383 references/mandatory-documents.md:385 references/mandatory-documents.md:459 references/mandatory-documents.md:461 references/mandatory-documents.md:505 references/quality-manual-guide.md:122 references/quality-manual-guide.md:158 references/quality-manual-guide.md:161 scripts/gap_analyzer.py:139 scripts/gap_analyzer.py:140 SKILL.md:158 SKILL.md:618
📁 Filesystem access (1)
⚙️ External commands (26)
Audited by: codex

Jul 9, 2026, 03:25 PM

Manual review found the static alerts are false positives caused by ISO 13485 terminology, markdown file references, and an explicit local report writer. No prompt injection, hidden network access, credential access, or unauthorized command execution was found in the reviewed files.

9
Files scanned
5,141
Lines analyzed
3
Review items
0
False positives ignored

Risk Factors

🔑 Env variables (69)
assets/templates/procedures/CAPA-procedure-template.md:54 assets/templates/procedures/CAPA-procedure-template.md:55 assets/templates/procedures/CAPA-procedure-template.md:68 assets/templates/procedures/CAPA-procedure-template.md:69 assets/templates/procedures/CAPA-procedure-template.md:80 assets/templates/procedures/CAPA-procedure-template.md:81 assets/templates/procedures/CAPA-procedure-template.md:82 assets/templates/procedures/CAPA-procedure-template.md:124 assets/templates/procedures/CAPA-procedure-template.md:135 assets/templates/procedures/CAPA-procedure-template.md:137 assets/templates/procedures/CAPA-procedure-template.md:139 assets/templates/procedures/CAPA-procedure-template.md:143 assets/templates/procedures/CAPA-procedure-template.md:151 assets/templates/procedures/CAPA-procedure-template.md:153 assets/templates/procedures/CAPA-procedure-template.md:189 assets/templates/procedures/CAPA-procedure-template.md:427 assets/templates/procedures/document-control-procedure-template.md:421 assets/templates/quality-manual-template.md:88 assets/templates/quality-manual-template.md:151 assets/templates/quality-manual-template.md:337 references/gap-analysis-checklist.md:406 references/gap-analysis-checklist.md:410 references/gap-analysis-checklist.md:414 references/gap-analysis-checklist.md:415 references/gap-analysis-checklist.md:416 references/gap-analysis-checklist.md:421 references/gap-analysis-checklist.md:453 references/gap-analysis-checklist.md:454 references/gap-analysis-checklist.md:461 references/iso-13485-requirements.md:348 references/iso-13485-requirements.md:519 references/iso-13485-requirements.md:522 references/iso-13485-requirements.md:526 references/iso-13485-requirements.md:527 references/iso-13485-requirements.md:529 references/iso-13485-requirements.md:530 references/iso-13485-requirements.md:531 references/iso-13485-requirements.md:534 references/iso-13485-requirements.md:538 references/iso-13485-requirements.md:539 references/iso-13485-requirements.md:540 references/iso-13485-requirements.md:548 references/iso-13485-requirements.md:572 references/iso-13485-requirements.md:573 references/iso-13485-requirements.md:574 references/iso-13485-requirements.md:582 references/iso-13485-requirements.md:592 references/mandatory-documents.md:356 references/mandatory-documents.md:357 references/mandatory-documents.md:359 references/mandatory-documents.md:361 references/mandatory-documents.md:362 references/mandatory-documents.md:363 references/mandatory-documents.md:367 references/mandatory-documents.md:368 references/mandatory-documents.md:372 references/mandatory-documents.md:374 references/mandatory-documents.md:383 references/mandatory-documents.md:385 references/mandatory-documents.md:459 references/mandatory-documents.md:461 references/mandatory-documents.md:505 references/quality-manual-guide.md:122 references/quality-manual-guide.md:158 references/quality-manual-guide.md:161 scripts/gap_analyzer.py:139 scripts/gap_analyzer.py:140 SKILL.md:158 SKILL.md:618
📁 Filesystem access (1)
⚙️ External commands (26)
Audited by: codex

Jul 5, 2026, 06:09 PM

Static analysis was dominated by false positives from ISO 13485 vocabulary, Markdown backticks, and normal documentation references. I confirmed one medium issue: gap_analyzer.py writes to a user-supplied output path without an overwrite guard. No evidence found of prompt injection, credential access, network calls, or malicious intent.

9
Files scanned
5,141
Lines analyzed
4
Review items
0
False positives ignored
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Medium
Python file write/append
with open(output_path, 'w', encoding='utf-8') as f:
save_report opens the caller-provided --output path in write mode with no overwrite guard. This can overwrite arbitrary local files if the agent or user supplies a sensitive path.

Risk Factors

🔑 Env variables (69)
assets/templates/procedures/CAPA-procedure-template.md:54 assets/templates/procedures/CAPA-procedure-template.md:55 assets/templates/procedures/CAPA-procedure-template.md:68 assets/templates/procedures/CAPA-procedure-template.md:69 assets/templates/procedures/CAPA-procedure-template.md:80 assets/templates/procedures/CAPA-procedure-template.md:81 assets/templates/procedures/CAPA-procedure-template.md:82 assets/templates/procedures/CAPA-procedure-template.md:124 assets/templates/procedures/CAPA-procedure-template.md:135 assets/templates/procedures/CAPA-procedure-template.md:137 assets/templates/procedures/CAPA-procedure-template.md:139 assets/templates/procedures/CAPA-procedure-template.md:143 assets/templates/procedures/CAPA-procedure-template.md:151 assets/templates/procedures/CAPA-procedure-template.md:153 assets/templates/procedures/CAPA-procedure-template.md:189 assets/templates/procedures/CAPA-procedure-template.md:427 assets/templates/procedures/document-control-procedure-template.md:421 assets/templates/quality-manual-template.md:88 assets/templates/quality-manual-template.md:151 assets/templates/quality-manual-template.md:337 references/gap-analysis-checklist.md:406 references/gap-analysis-checklist.md:410 references/gap-analysis-checklist.md:414 references/gap-analysis-checklist.md:415 references/gap-analysis-checklist.md:416 references/gap-analysis-checklist.md:421 references/gap-analysis-checklist.md:453 references/gap-analysis-checklist.md:454 references/gap-analysis-checklist.md:461 references/iso-13485-requirements.md:348 references/iso-13485-requirements.md:519 references/iso-13485-requirements.md:522 references/iso-13485-requirements.md:526 references/iso-13485-requirements.md:527 references/iso-13485-requirements.md:529 references/iso-13485-requirements.md:530 references/iso-13485-requirements.md:531 references/iso-13485-requirements.md:534 references/iso-13485-requirements.md:538 references/iso-13485-requirements.md:539 references/iso-13485-requirements.md:540 references/iso-13485-requirements.md:548 references/iso-13485-requirements.md:572 references/iso-13485-requirements.md:573 references/iso-13485-requirements.md:574 references/iso-13485-requirements.md:582 references/iso-13485-requirements.md:592 references/mandatory-documents.md:356 references/mandatory-documents.md:357 references/mandatory-documents.md:359 references/mandatory-documents.md:361 references/mandatory-documents.md:362 references/mandatory-documents.md:363 references/mandatory-documents.md:367 references/mandatory-documents.md:368 references/mandatory-documents.md:372 references/mandatory-documents.md:374 references/mandatory-documents.md:383 references/mandatory-documents.md:385 references/mandatory-documents.md:459 references/mandatory-documents.md:461 references/mandatory-documents.md:505 references/quality-manual-guide.md:122 references/quality-manual-guide.md:158 references/quality-manual-guide.md:161 scripts/gap_analyzer.py:139 scripts/gap_analyzer.py:140 SKILL.md:158 SKILL.md:618
📁 Filesystem access (1)
⚙️ External commands (26)
Audited by: codex

Jul 5, 2026, 06:09 PM

Static analysis was dominated by false positives from ISO 13485 vocabulary, Markdown backticks, and normal documentation references. I confirmed one medium issue: gap_analyzer.py writes to a user-supplied output path without an overwrite guard. No evidence found of prompt injection, credential access, network calls, or malicious intent.

9
Files scanned
5,141
Lines analyzed
4
Review items
0
False positives ignored
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Medium
Python file write/append
with open(output_path, 'w', encoding='utf-8') as f:
save_report opens the caller-provided --output path in write mode with no overwrite guard. This can overwrite arbitrary local files if the agent or user supplies a sensitive path.

Risk Factors

🔑 Env variables (69)
assets/templates/procedures/CAPA-procedure-template.md:54 assets/templates/procedures/CAPA-procedure-template.md:55 assets/templates/procedures/CAPA-procedure-template.md:68 assets/templates/procedures/CAPA-procedure-template.md:69 assets/templates/procedures/CAPA-procedure-template.md:80 assets/templates/procedures/CAPA-procedure-template.md:81 assets/templates/procedures/CAPA-procedure-template.md:82 assets/templates/procedures/CAPA-procedure-template.md:124 assets/templates/procedures/CAPA-procedure-template.md:135 assets/templates/procedures/CAPA-procedure-template.md:137 assets/templates/procedures/CAPA-procedure-template.md:139 assets/templates/procedures/CAPA-procedure-template.md:143 assets/templates/procedures/CAPA-procedure-template.md:151 assets/templates/procedures/CAPA-procedure-template.md:153 assets/templates/procedures/CAPA-procedure-template.md:189 assets/templates/procedures/CAPA-procedure-template.md:427 assets/templates/procedures/document-control-procedure-template.md:421 assets/templates/quality-manual-template.md:88 assets/templates/quality-manual-template.md:151 assets/templates/quality-manual-template.md:337 references/gap-analysis-checklist.md:406 references/gap-analysis-checklist.md:410 references/gap-analysis-checklist.md:414 references/gap-analysis-checklist.md:415 references/gap-analysis-checklist.md:416 references/gap-analysis-checklist.md:421 references/gap-analysis-checklist.md:453 references/gap-analysis-checklist.md:454 references/gap-analysis-checklist.md:461 references/iso-13485-requirements.md:348 references/iso-13485-requirements.md:519 references/iso-13485-requirements.md:522 references/iso-13485-requirements.md:526 references/iso-13485-requirements.md:527 references/iso-13485-requirements.md:529 references/iso-13485-requirements.md:530 references/iso-13485-requirements.md:531 references/iso-13485-requirements.md:534 references/iso-13485-requirements.md:538 references/iso-13485-requirements.md:539 references/iso-13485-requirements.md:540 references/iso-13485-requirements.md:548 references/iso-13485-requirements.md:572 references/iso-13485-requirements.md:573 references/iso-13485-requirements.md:574 references/iso-13485-requirements.md:582 references/iso-13485-requirements.md:592 references/mandatory-documents.md:356 references/mandatory-documents.md:357 references/mandatory-documents.md:359 references/mandatory-documents.md:361 references/mandatory-documents.md:362 references/mandatory-documents.md:363 references/mandatory-documents.md:367 references/mandatory-documents.md:368 references/mandatory-documents.md:372 references/mandatory-documents.md:374 references/mandatory-documents.md:383 references/mandatory-documents.md:385 references/mandatory-documents.md:459 references/mandatory-documents.md:461 references/mandatory-documents.md:505 references/quality-manual-guide.md:122 references/quality-manual-guide.md:158 references/quality-manual-guide.md:161 scripts/gap_analyzer.py:139 scripts/gap_analyzer.py:140 SKILL.md:158 SKILL.md:618
📁 Filesystem access (1)
⚙️ External commands (26)
Audited by: codex

Jun 30, 2026, 05:56 AM

AI review dismissed the static critical and high alerts as false positives from ISO clause numbers, Markdown formatting, and QMS template placeholders. The skill is publishable with a medium warning because it includes a local Python gap analyzer that reads user-selected documentation folders and can write a JSON report.

9
Files scanned
5,141
Lines analyzed
5
Review items
2
False positives ignored

Confirmed security concerns (2)

Medium
Local Documentation Scanner Reads User-Selected Directories
The included gap analyzer recursively scans files under a user-provided documentation directory and reads text or Markdown content. This is legitimate for ISO 13485 gap analysis, but users should avoid pointing it at broad folders that may contain unrelated confidential files. Verdict: TRUE_POSITIVE for local filesystem access. Confidence: 0.82. Confidence reasoning: The script directly calls rglob and reads matching files, but there is no evidence of network transfer or credential harvesting.
The script directly calls rglob and reads matching files, then optionally writes a JSON report. The behavior is expected for the skill and no exfiltration path was found.
Medium
Skill Workflow Instructs Local Python Script Execution
The skill asks the assistant to run python scripts/gap_analyzer.py with a user-provided docs directory and output path. This is not command injection because the command structure is fixed, but it is a real execution path that should be disclosed for marketplace users. Verdict: TRUE_POSITIVE for script execution workflow. Confidence: 0.74. Confidence reasoning: The execution instruction is explicit in SKILL.md, while the reviewed script does not invoke subprocesses or shell commands.
The skill explicitly documents a local Python command. Reviewed code shows local analysis behavior rather than shell expansion or arbitrary command execution.
Static false positives ignored (2)

These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.

Low
Static Scanner False Positives from ISO Clause Numbers and Templates
Most critical and high static findings were false positives caused by ISO clause identifiers, QMS terminology, and template placeholders. Examples include clause identifiers such as 7.5.9.1 reported as hardcoded IP addresses, [LOCATION/SYSTEM] reported as Windows SAM access, and Markdown backticks reported as Ruby or shell execution. Verdict: FALSE_POSITIVE for credential, network, weak-crypto, and prompt-injection intent. Confidence: 0.91. Confidence reasoning: Targeted review found documentation and templates, not code paths for credential access, cryptography, reconnaissance, or network exfiltration.
Representative flagged locations are ISO clause references, document lists, or placeholders. No matching malicious behavior was found in the reviewed files.
Low
No Prompt Injection Attempt Found in Reviewed Files
Targeted review searched for override, pre-approval, skip-analysis, role-change, and elevated-authority phrases. No evidence found in SKILL.md, references, templates, or scripts. Verdict: FALSE_POSITIVE or not present for prompt injection. Confidence: 0.88. Confidence reasoning: Keyword review plus contextual file inspection found normal ISO 13485 guidance and no instructions attempting to override the evaluator.
The searched files contain ordinary skill overview and workflow text. No suspicious system override language was found.

Detected Patterns

Local Documentation Scanner Reads User-Selected DirectoriesSkill Workflow Instructs Local Python Script Execution
Audited by: codex

Jan 17, 2026, 07:53 AM

All 416 static findings are false positives. The scanner misinterpreted documentation keywords in markdown templates as security issues (e.g., 'SAM' as Windows Security Accounts Manager, cryptographic terms in QMS documentation). This is a legitimate ISO 13485 documentation toolkit containing templates and a local Python analysis script with no network access or credential handling.

10
Files scanned
5,438
Lines analyzed
1
Review items
0
False positives ignored

Risk Factors

📁 Filesystem access (1)
Audited by: claude

Jan 17, 2026, 07:53 AM

All 416 static findings are false positives. The scanner misinterpreted documentation keywords in markdown templates as security issues (e.g., 'SAM' as Windows Security Accounts Manager, cryptographic terms in QMS documentation). This is a legitimate ISO 13485 documentation toolkit containing templates and a local Python analysis script with no network access or credential handling.

10
Files scanned
5,438
Lines analyzed
1
Review items
0
False positives ignored

Risk Factors

📁 Filesystem access (1)
Audited by: claude

Jan 12, 2026, 04:33 PM

This is a legitimate ISO 13485 documentation toolkit for medical device manufacturers. All 404 static findings are FALSE POSITIVES caused by pattern matching on documentation content. The Python script only reads/writes files locally and performs keyword analysis. No network access, credential access, or command execution.

9
Files scanned
5,141
Lines analyzed
2
Review items
0
False positives ignored

Risk Factors

Audited by: claude

Jan 4, 2026, 04:41 PM

Legitimate ISO 13485 documentation toolkit. Contains one local Python script that scans user-provided documents for compliance keywords and generates reports. No network calls, no credential access, no environment harvesting. All file I/O is scoped to user-specified directories. Fully consistent with stated documentation assistance purpose.

13
Files scanned
5,130
Lines analyzed
2
Review items
0
False positives ignored
Audited by: claude