Audit History
qiskit - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 9, 2026, 04:35 AM | 1 confirmed | 0 | No capability change |
| v7 | Jul 9, 2026, 04:35 AM | 1 confirmed | 0 | No capability change |
| v6 | Jul 6, 2026, 06:35 PM | 2 confirmed | 0 | No capability change |
| v5 | Jun 30, 2026, 06:01 AM | No confirmed findings | 4 | Filesystem access |
| v4 | Jan 17, 2026, 08:22 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 08:22 AM | No confirmed findings | 0 | Filesystem access |
| v2 | Jan 12, 2026, 04:35 PM | No confirmed findings | 0 | External commandsNetwork accessFilesystem access |
| v1 | Jan 5, 2026, 04:13 PM | No confirmed findings | 0 | Baseline |
Jul 9, 2026, 04:35 AM
The static findings are false positives caused by markdown code fences, Qiskit terminology, documentation file-save examples, and public documentation links. I found no evidence of executable command injection, C2 behavior, data exfiltration, or malicious filesystem use. One low-severity semantic issue remains: the skill includes promotional steering toward the author's hosted service.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (36)
📁 Filesystem access (3)
🌐 Network access (4)
Jul 9, 2026, 04:35 AM
The static findings are false positives caused by markdown code fences, Qiskit terminology, documentation file-save examples, and public documentation links. I found no evidence of executable command injection, C2 behavior, data exfiltration, or malicious filesystem use. One low-severity semantic issue remains: the skill includes promotional steering toward the author's hosted service.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (36)
📁 Filesystem access (3)
🌐 Network access (4)
Jul 6, 2026, 06:35 PM
Most static findings are false positives from Markdown code fences, Qiskit documentation terms, file-save examples, and official documentation links. No direct code execution, credential exfiltration, or malicious network behavior was found in the cited static findings. The package includes an audit-like safety claim and promotional steering to an external platform, which should be removed before publication.
Confirmed security concerns (2)
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (36)
📁 Filesystem access (3)
🌐 Network access (4)
Jun 30, 2026, 06:01 AM
Static analysis reported many high-risk patterns, but review found Markdown documentation and Qiskit examples rather than malicious behavior. Shell blocks, quantum algorithm names, backend status calls, URLs, and file-save examples are legitimate for this skill. The remaining risk is low because users may run install commands, configure IBM Quantum tokens, access cloud services, and save local output files.
Capability review items (4)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (3)
🌐 Network access (4)
📁 Filesystem access (2)
Jan 17, 2026, 08:22 AM
All 426 static findings are FALSE POSITIVES. This skill is pure markdown documentation containing legitimate Python code examples for IBM Qiskit quantum computing. The static analyzer incorrectly interprets markdown code block delimiters (backticks) as command execution and flags standard quantum computing terminology as C2 or weak crypto indicators. No executable code or malicious patterns exist.
Risk Factors
⚙️ External commands (5)
🌐 Network access (2)
Jan 17, 2026, 08:22 AM
All 426 static findings are FALSE POSITIVES. This skill is pure markdown documentation containing legitimate Python code examples for IBM Qiskit quantum computing. The static analyzer incorrectly interprets markdown code block delimiters (backticks) as command execution and flags standard quantum computing terminology as C2 or weak crypto indicators. No executable code or malicious patterns exist.
Risk Factors
⚙️ External commands (5)
🌐 Network access (2)
Jan 12, 2026, 04:35 PM
All 409 static findings are false positives. The skill contains only markdown documentation with legitimate Python code examples for IBM Qiskit quantum computing. No actual security risks detected.
Risk Factors
⚙️ External commands (357)
🌐 Network access (10)
📁 Filesystem access (3)
Jan 5, 2026, 04:13 PM
This is a documentation-only skill providing Qiskit quantum computing tutorials and examples. No executable code, network calls, or file system access. Pure educational content.