Audit History
qutip - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 6, 2026, 06:40 PM | 1 confirmed | 0 | No capability change |
| v6 | Jul 6, 2026, 06:40 PM | 1 confirmed | 0 | No capability change |
| v5 | Jun 30, 2026, 06:05 AM | No confirmed findings | 1 | No capability change |
| v4 | Jan 17, 2026, 06:02 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 06:02 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 12, 2026, 04:36 PM | No confirmed findings | 0 | Contains scriptsExternal commandsNetwork access |
| v1 | Jan 4, 2026, 04:41 PM | No confirmed findings | 0 | Baseline |
Jul 6, 2026, 06:40 PM
AI review found no prompt injection, credential access, data exfiltration, or executable script behavior. The static script and backtick findings are false positives caused by Markdown formatting and QuTiP API names; one low-severity semantic issue remains for vendor service promotion.
Confirmed security concerns (1)
Risk Factors
⚡ Contains scripts (3)
⚙️ External commands (46)
🌐 Network access (4)
Jul 6, 2026, 06:40 PM
AI review found no prompt injection, credential access, data exfiltration, or executable script behavior. The static script and backtick findings are false positives caused by Markdown formatting and QuTiP API names; one low-severity semantic issue remains for vendor service promotion.
Confirmed security concerns (1)
Risk Factors
⚡ Contains scripts (3)
⚙️ External commands (46)
🌐 Network access (4)
Jun 30, 2026, 06:05 AM
AI review found the static high-risk patterns are false positives caused by Markdown fences and QuTiP scientific terms such as destroy, Floquet modes, and QFunc.eval. The confirmed concerns are low risk: package installation commands, documentation URLs, and a vendor promotion instruction for K-Dense Web. No evidence found of malicious code execution, credential access, data exfiltration, or prompt injection override text.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚡ Contains scripts (2)
⚙️ External commands (3)
🌐 Network access (2)
Jan 17, 2026, 06:02 AM
Documentation-only skill containing markdown files with QuTiP code examples. All 405 static findings are FALSE POSITIVES from the analyzer misinterpreting markdown syntax as security patterns. No executable code, network calls, file system access, or external commands exist.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (2)
🌐 Network access (1)
Jan 17, 2026, 06:02 AM
Documentation-only skill containing markdown files with QuTiP code examples. All 405 static findings are FALSE POSITIVES from the analyzer misinterpreting markdown syntax as security patterns. No executable code, network calls, file system access, or external commands exist.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (2)
🌐 Network access (1)
Jan 12, 2026, 04:36 PM
This is a documentation-only skill containing markdown files with QuTiP code examples. ALL 397 static findings are FALSE POSITIVES caused by the analyzer misinterpreting documentation syntax. No executable code, network calls, file system access, or external commands exist in this skill.
Risk Factors
⚡ Contains scripts (3)
⚙️ External commands (348)
🌐 Network access (4)
Jan 4, 2026, 04:41 PM
Reviewed 9 documentation files with 2717 lines of code. No executable scripts, network calls, or malicious patterns found. This is a pure documentation skill providing QuTiP usage guidance.