Audit History
peer-review - 10 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v10 Latest | Jul 9, 2026, 02:05 PM | No confirmed findings | 0 | No capability change |
| v9 | Jul 9, 2026, 02:05 PM | No confirmed findings | 0 | No capability change |
| v8 | Jul 5, 2026, 05:32 PM | 1 confirmed | 2 | No capability change |
| v7 | Jul 5, 2026, 05:32 PM | 1 confirmed | 2 | Network access |
| v6 | Jun 30, 2026, 05:56 AM | 1 confirmed | 2 | No capability change |
| v5 | Jan 21, 2026, 05:36 PM | No confirmed findings | 0 | No capability change |
| v4 | Jan 17, 2026, 07:16 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 07:16 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 12, 2026, 04:26 PM | No confirmed findings | 0 | Network accessExternal commands |
| v1 | Jan 4, 2026, 05:33 PM | No confirmed findings | 0 | Baseline |
Jul 9, 2026, 02:05 PM
All 17 static findings were assessed as false positives. The blocker matches are scientific review checklist prose, and the external command matches are Markdown fences or documented local helper examples. No prompt injection, exfiltration intent, credential access, or destructive behavior was found.
Risk Factors
Jul 9, 2026, 02:05 PM
All 17 static findings were assessed as false positives. The blocker matches are scientific review checklist prose, and the external command matches are Markdown fences or documented local helper examples. No prompt injection, exfiltration intent, credential access, or destructive behavior was found.
Risk Factors
Jul 5, 2026, 05:32 PM
Most static findings are false positives from scientific review terminology and Markdown fences. Two findings are confirmed because the skill instructs agents to run local Python scripts through Bash, and one low-severity semantic issue notes external service steering for confidential workflows.
Confirmed security concerns (1)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
Jul 5, 2026, 05:32 PM
Most static findings are false positives from scientific review terminology and Markdown fences. Two findings are confirmed because the skill instructs agents to run local Python scripts through Bash, and one low-severity semantic issue notes external service steering for confidential workflows.
Confirmed security concerns (1)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
Jun 30, 2026, 05:56 AM
Static analysis reported many high-risk weak-cryptography and reconnaissance patterns, but review showed these are false positives from scientific review terminology and reference links. The remaining concern is legitimate but elevated: this community skill allows Bash and includes local Python command examples for schematic generation and slide conversion, so users should review commands before execution.
Confirmed security concerns (1)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (13)
⚙️ External commands (3)
Detected Patterns
Jan 21, 2026, 05:36 PM
All 106 static findings are false positives. The skill is a scientific peer review documentation tool. Detected 'C2 keywords' are false positives from legitimate terms like 'command-line'. 'Weak cryptographic algorithm' references are educational content in reference materials for evaluating manuscript methodology. Backtick patterns are markdown code formatting in documentation examples. No actual malicious code execution patterns exist.
Risk Factors
🌐 Network access (13)
Jan 17, 2026, 07:16 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
🌐 Network access (13)
Detected Patterns
Jan 17, 2026, 07:16 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
🌐 Network access (13)
Detected Patterns
Jan 12, 2026, 04:26 PM
All 94 static findings are FALSE POSITIVES. This is a documentation-only skill containing markdown reference materials for scientific peer review. The static analyzer misidentified documentation text (e.g., 'hardcoded URLs' that are reference links, 'shell backticks' that are markdown code examples) as security issues. There is no executable code, no network calls, no command execution - only documentation content.
Risk Factors
🌐 Network access (13)
Jan 4, 2026, 05:33 PM
No credential access, environment harvesting, or network exfiltration patterns detected. Content is instructional and aligned with peer review tasks.