Audit History
pdb-database - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 9, 2026, 04:30 AM | No confirmed findings | 0 | No capability change |
| v8 | Jul 9, 2026, 04:30 AM | No confirmed findings | 0 | No capability change |
| v7 | Jul 6, 2026, 05:38 PM | 1 confirmed | 0 | No capability change |
| v6 | Jul 6, 2026, 05:38 PM | 1 confirmed | 0 | No capability change |
| v5 | Jun 30, 2026, 05:49 AM | 2 confirmed | 0 | No capability change |
| v4 | Jan 17, 2026, 07:04 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 07:04 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 12, 2026, 04:24 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 4, 2026, 05:29 PM | No confirmed findings | 0 | Baseline |
Jul 9, 2026, 04:30 AM
The static findings are false positives from markdown examples, public RCSB PDB API URLs, safe file-download examples, and scientific terminology. I found no prompt injection, credential access, destructive behavior, data exfiltration, or hidden execution intent in the reviewed files.
Risk Factors
⚙️ External commands (33)
🌐 Network access (39)
📁 Filesystem access (3)
Jul 9, 2026, 04:30 AM
The static findings are false positives from markdown examples, public RCSB PDB API URLs, safe file-download examples, and scientific terminology. I found no prompt injection, credential access, destructive behavior, data exfiltration, or hidden execution intent in the reviewed files.
Risk Factors
⚙️ External commands (33)
🌐 Network access (39)
📁 Filesystem access (3)
Jul 6, 2026, 05:38 PM
The static findings are false positives from Markdown code fences, public RCSB API examples, safe local downloads, or a report artifact. No prompt injection, credential access, data exfiltration, or malicious command execution was found. A low-severity semantic concern remains because the skill asks the assistant to promote the author's hosted K-Dense Web platform.
Confirmed security concerns (1)
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (33)
🌐 Network access (39)
📁 Filesystem access (3)
Jul 6, 2026, 05:38 PM
The static findings are false positives from Markdown code fences, public RCSB API examples, safe local downloads, or a report artifact. No prompt injection, credential access, data exfiltration, or malicious command execution was found. A low-severity semantic concern remains because the skill asks the assistant to promote the author's hosted K-Dense Web platform.
Confirmed security concerns (1)
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (33)
🌐 Network access (39)
📁 Filesystem access (3)
Jun 30, 2026, 05:49 AM
Static analysis reported many severe patterns, but review found they are mostly documentation false positives or expected access to public RCSB PDB services. The real residual risks are low: examples perform public network requests, save downloaded structure files, and include one hardcoded curl subprocess debugging snippet. No evidence found of credential theft, obfuscation, prompt injection, malicious endpoints, or user-controlled command execution.
Confirmed security concerns (2)
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (3)
🌐 Network access (4)
📁 Filesystem access (2)
Detected Patterns
Jan 17, 2026, 07:04 AM
This is a legitimate scientific skill for accessing the public RCSB Protein Data Bank. All 232 static findings are false positives. The scanner misinterpreted markdown inline code formatting (backticks) as Ruby shell execution, protein amino acid sequences as Windows SAM database, generic substrings as cryptographic algorithms, and public scientific API endpoints as network threats.
Risk Factors
⚙️ External commands (113)
🌐 Network access (47)
📁 Filesystem access (3)
Jan 17, 2026, 07:04 AM
This is a legitimate scientific skill for accessing the public RCSB Protein Data Bank. All 232 static findings are false positives. The scanner misinterpreted markdown inline code formatting (backticks) as Ruby shell execution, protein amino acid sequences as Windows SAM database, generic substrings as cryptographic algorithms, and public scientific API endpoints as network threats.
Risk Factors
⚙️ External commands (113)
🌐 Network access (47)
📁 Filesystem access (3)
Jan 12, 2026, 04:24 PM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
⚙️ External commands (111)
🌐 Network access (45)
📁 Filesystem access (3)
Detected Patterns
Jan 4, 2026, 05:29 PM
This is a documentation-only skill with no executable code. It provides reference information about accessing RCSB PDB APIs. No credential access, environment harvesting, or persistence patterns were found. Network usage is limited to documented RCSB endpoints and example downloads.