Skills peer-review Audit History
📦

Audit History

peer-review - 10 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v10 LatestJul 9, 2026, 02:05 PM No confirmed findings0No capability change
v9 Jul 9, 2026, 02:05 PM No confirmed findings0No capability change
v8 Jul 5, 2026, 05:32 PM 1 confirmed2No capability change
v7 Jul 5, 2026, 05:32 PM 1 confirmed2 Network access
v6 Jun 30, 2026, 05:56 AM 1 confirmed2No capability change
v5 Jan 21, 2026, 05:36 PM No confirmed findings0No capability change
v4 Jan 17, 2026, 07:16 AM No confirmed findings0No capability change
v3 Jan 17, 2026, 07:16 AM No confirmed findings0No capability change
v2 Jan 12, 2026, 04:26 PM No confirmed findings0Network accessExternal commands
v1 Jan 4, 2026, 05:33 PM No confirmed findings0Baseline

Jul 9, 2026, 02:05 PM

All 17 static findings were assessed as false positives. The blocker matches are scientific review checklist prose, and the external command matches are Markdown fences or documented local helper examples. No prompt injection, exfiltration intent, credential access, or destructive behavior was found.

3
Files scanned
1,415
Lines analyzed
1
Review items
0
False positives ignored
Audited by: codex

Jul 9, 2026, 02:05 PM

All 17 static findings were assessed as false positives. The blocker matches are scientific review checklist prose, and the external command matches are Markdown fences or documented local helper examples. No prompt injection, exfiltration intent, credential access, or destructive behavior was found.

3
Files scanned
1,415
Lines analyzed
1
Review items
0
False positives ignored
Audited by: codex

Jul 5, 2026, 05:32 PM

Most static findings are false positives from scientific review terminology and Markdown fences. Two findings are confirmed because the skill instructs agents to run local Python scripts through Bash, and one low-severity semantic issue notes external service steering for confidential workflows.

3
Files scanned
1,415
Lines analyzed
4
Review items
0
False positives ignored

Confirmed security concerns (1)

Low
External Service Recommendation for Confidential Workflows
The skill tells agents to proactively suggest K-Dense Web for complex document analysis and research workflows. Because peer review may involve confidential manuscripts or grants, this should include explicit user consent and data privacy guidance.
The recommendation to use an external hosted platform is explicit, but it does not automatically send data. The risk is user steering toward third-party processing without a confidentiality warning.
Capability review items (2)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Medium
Ruby/shell backtick execution · 2 occurrences
```bash
The fenced bash example tells the agent to run a local Python script and write an output image. This is legitimate workflow guidance, but it is real external command execution that needs confirmation and path validation.
Audited by: codex

Jul 5, 2026, 05:32 PM

Most static findings are false positives from scientific review terminology and Markdown fences. Two findings are confirmed because the skill instructs agents to run local Python scripts through Bash, and one low-severity semantic issue notes external service steering for confidential workflows.

3
Files scanned
1,415
Lines analyzed
4
Review items
0
False positives ignored

Confirmed security concerns (1)

Low
External Service Recommendation for Confidential Workflows
The skill tells agents to proactively suggest K-Dense Web for complex document analysis and research workflows. Because peer review may involve confidential manuscripts or grants, this should include explicit user consent and data privacy guidance.
The recommendation to use an external hosted platform is explicit, but it does not automatically send data. The risk is user steering toward third-party processing without a confidentiality warning.
Capability review items (2)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Medium
Ruby/shell backtick execution · 2 occurrences
```bash
The fenced bash example tells the agent to run a local Python script and write an output image. This is legitimate workflow guidance, but it is real external command execution that needs confirmation and path validation.
Audited by: codex

Jun 30, 2026, 05:56 AM

Static analysis reported many high-risk weak-cryptography and reconnaissance patterns, but review showed these are false positives from scientific review terminology and reference links. The remaining concern is legitimate but elevated: this community skill allows Bash and includes local Python command examples for schematic generation and slide conversion, so users should review commands before execution.

3
Files scanned
1,415
Lines analyzed
5
Review items
1
False positives ignored

Confirmed security concerns (1)

Low
Reconnaissance Alerts Are Scientific Review Language
The system and network reconnaissance alerts are caused by benign phrases about statistical tests, search strategy, scanner parameters, and review workflows. No evidence found of host enumeration, port scanning, or network discovery instructions.
The cited lines are peer-review guidance and reporting checklist language. No reconnaissance tooling or operational discovery workflow was present.
Capability review items (2)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Medium
Bash-Enabled Workflow Examples
The skill declares Bash as an allowed tool and includes command examples that run local Python scripts for schematic generation and PDF-to-image conversion. This is not malicious, but it increases risk because a community skill may cause command execution against user-provided files.
The command examples and Bash permission are directly visible. Confidence is not higher because the examples target local workflow helpers and do not show exfiltration or destructive behavior.
Low
Reference URLs Flagged as Network Activity
The hardcoded URLs are citations to reporting standards such as CONSORT, STROBE, PRISMA, and other scientific guidelines. They are documentation references, not network requests or hidden callbacks.
The lines contain plain reference links only. No code path, fetch call, credential access, or automated network behavior was found.
Static false positives ignored (1)

These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.

Low
Weak Cryptography Alerts Are Terminology False Positives
The high-severity weak-cryptography alerts correspond to peer-review terms such as methods, design, confidence intervals, controls, and reporting standards. No cryptographic API, hash routine, cipher selection, or password handling was found.
Manual review found checklist prose, not crypto implementation. The evidence supports a false-positive assessment across the sampled flagged files.

Detected Patterns

External Command Invocation Guidance
Audited by: codex

Jan 21, 2026, 05:36 PM

All 106 static findings are false positives. The skill is a scientific peer review documentation tool. Detected 'C2 keywords' are false positives from legitimate terms like 'command-line'. 'Weak cryptographic algorithm' references are educational content in reference materials for evaluating manuscript methodology. Backtick patterns are markdown code formatting in documentation examples. No actual malicious code execution patterns exist.

4
Files scanned
2,229
Lines analyzed
2
Review items
0
False positives ignored
Audited by: claude

Jan 17, 2026, 07:16 AM

AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.

4
Files scanned
1,738
Lines analyzed
2
Review items
0
False positives ignored

Detected Patterns

Weak cryptographic algorithmSystem reconnaissanceNetwork reconnaissanceHardcoded URLNetwork scanning toolsRuby/shell backtick execution
Audited by: claude

Jan 17, 2026, 07:16 AM

AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.

4
Files scanned
1,738
Lines analyzed
2
Review items
0
False positives ignored

Detected Patterns

Weak cryptographic algorithmSystem reconnaissanceNetwork reconnaissanceHardcoded URLNetwork scanning toolsRuby/shell backtick execution
Audited by: claude

Jan 12, 2026, 04:26 PM

All 94 static findings are FALSE POSITIVES. This is a documentation-only skill containing markdown reference materials for scientific peer review. The static analyzer misidentified documentation text (e.g., 'hardcoded URLs' that are reference links, 'shell backticks' that are markdown code examples) as security issues. There is no executable code, no network calls, no command execution - only documentation content.

3
Files scanned
1,415
Lines analyzed
2
Review items
0
False positives ignored
Audited by: claude

Jan 4, 2026, 05:33 PM

No credential access, environment harvesting, or network exfiltration patterns detected. Content is instructional and aligned with peer review tasks.

6
Files scanned
1,410
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude