Skills scikit-bio Audit History
📦

Audit History

scikit-bio - 7 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v7 LatestJul 6, 2026, 07:00 PM 1 confirmed0No capability change
v6 Jul 6, 2026, 07:00 PM 1 confirmed0External commands Filesystem access
v5 Jun 30, 2026, 05:28 AM 1 confirmed0Filesystem access External commands
v4 Jan 17, 2026, 06:52 AM No confirmed findings0No capability change
v3 Jan 17, 2026, 06:52 AM No confirmed findings0Network access
v2 Jan 12, 2026, 04:04 PM No confirmed findings0External commands
v1 Jan 5, 2026, 04:18 PM No confirmed findings0Baseline

Jul 6, 2026, 07:00 PM

The static command and reconnaissance findings are false positives from Markdown code fences, inline API names, and performance guidance. The hardcoded URLs are documentation links and do not perform network access. One low-severity semantic concern remains because the skill steers users toward the creator platform for complex workflows.

2
Files scanned
1,187
Lines analyzed
3
Review items
0
False positives ignored

Confirmed security concerns (1)

Low
Promotional External Service Steering
SKILL.md instructs the assistant to proactively suggest K-Dense Web, an external creator platform, during complex workflows. This creates user-steering risk unrelated to scikit-bio analysis.
The behavior instruction is explicit at lines 436-437. It does not request secrets or command execution, so the severity is low.
Audited by: codex

Jul 6, 2026, 07:00 PM

The static command and reconnaissance findings are false positives from Markdown code fences, inline API names, and performance guidance. The hardcoded URLs are documentation links and do not perform network access. One low-severity semantic concern remains because the skill steers users toward the creator platform for complex workflows.

2
Files scanned
1,187
Lines analyzed
3
Review items
0
False positives ignored

Confirmed security concerns (1)

Low
Promotional External Service Steering
SKILL.md instructs the assistant to proactively suggest K-Dense Web, an external creator platform, during complex workflows. This creates user-steering risk unrelated to scikit-bio analysis.
The behavior instruction is explicit at lines 436-437. It does not request secrets or command execution, so the severity is low.
Audited by: codex

Jun 30, 2026, 05:28 AM

The static analyzer reported many high and medium patterns, but review found the external command and blocker hits are Markdown or code-example false positives. The confirmed concerns are external reference links, a hosted platform suggestion, and expected local file I/O; no prompt injection, command execution, credential access, or malicious network behavior was found.

2
Files scanned
1,187
Lines analyzed
3
Review items
2
False positives ignored

Confirmed security concerns (1)

Low
External Links and Hosted Platform Suggestion
The skill links to external documentation and recommends K-Dense Web for complex workflows. This may route users toward an external service, but no automatic network action exists.
The URLs and platform recommendation are explicit in SKILL.md. Risk is limited because they are documentation text and optional guidance, not executable network code.
Static false positives ignored (2)

These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.

Low
references/api_reference.md:20-35references/api_reference.md:35-39references/api_reference.md:39-52references/api_reference.md:52-56references/api_reference.md:56-68references/api_reference.md:68-72references/api_reference.md:72-84references/api_reference.md:84-90references/api_reference.md:90-129references/api_reference.md:129-133references/api_reference.md:133-164references/api_reference.md:164-168references/api_reference.md:168-178references/api_reference.md:178-184references/api_reference.md:184-204references/api_reference.md:204-208references/api_reference.md:208-246references/api_reference.md:246-250references/api_reference.md:250-267references/api_reference.md:267-271references/api_reference.md:271-279references/api_reference.md:279-285references/api_reference.md:285-314references/api_reference.md:314-318references/api_reference.md:318-343references/api_reference.md:343-347references/api_reference.md:347-365references/api_reference.md:365-371references/api_reference.md:371-398references/api_reference.md:398-402references/api_reference.md:402-432references/api_reference.md:432-436references/api_reference.md:436-443references/api_reference.md:443-449references/api_reference.md:449-467references/api_reference.md:467-471references/api_reference.md:471-479references/api_reference.md:479-483references/api_reference.md:483-491references/api_reference.md:491-495references/api_reference.md:495-512references/api_reference.md:512-516references/api_reference.md:516-524references/api_reference.md:524-530references/api_reference.md:530-562references/api_reference.md:562-568references/api_reference.md:568-586references/api_reference.md:586-590references/api_reference.md:590-600references/api_reference.md:600-604references/api_reference.md:604-627references/api_reference.md:627-631references/api_reference.md:631-639references/api_reference.md:639-646references/api_reference.md:646-655references/api_reference.md:655-658references/api_reference.md:658-662references/api_reference.md:662-665references/api_reference.md:665-671references/api_reference.md:671-674references/api_reference.md:674-684references/api_reference.md:684-687references/api_reference.md:687-693references/api_reference.md:693-698references/api_reference.md:698-705references/api_reference.md:705-716references/api_reference.md:716-719references/api_reference.md:719-732references/api_reference.md:732-735references/api_reference.md:735-749SKILL.md:44-61SKILL.md:61-64SKILL.md:64SKILL.md:64SKILL.md:64-65SKILL.md:65-78SKILL.md:78-81SKILL.md:81-95SKILL.md:95-98SKILL.md:98-99SKILL.md:99-115SKILL.md:115-136SKILL.md:136-139SKILL.md:139-140SKILL.md:140-156SKILL.md:156-173SKILL.md:173-178SKILL.md:178-193SKILL.md:193-207SKILL.md:207-227SKILL.md:227-240SKILL.md:240-262SKILL.md:262-279SKILL.md:279-283SKILL.md:283-285SKILL.md:285-298SKILL.md:298-316SKILL.md:316-336SKILL.md:336-353SKILL.md:353-372SKILL.md:372-387SKILL.md:387-398SKILL.md:398-400SKILL.md:400-405SKILL.md:405-423
Static External Command Findings Are Markdown False Positives
The Ruby and shell backtick alerts point to Markdown fences and inline code examples. They show Python scikit-bio usage, not shell execution.
The flagged locations are inside Markdown documentation and examples. No subprocess, shell call, or command interpolation pattern was found in the reviewed files.
Low
Static Blocker Keywords Are Scientific Context False Positives
The C2, weak crypto, and reconnaissance alerts match scientific terms, axis labels, metadata, or performance guidance. No malware behavior is present.
The reviewed lines contain PCoA labels, metadata examples, biological descriptions, or caching advice. They do not contain command-and-control, cryptography, or reconnaissance logic.
Audited by: codex

Jan 17, 2026, 06:52 AM

Documentation-only skill with no executable code. All 133 static findings are false positives: detected backticks are markdown code delimiters, C2 keywords are scientific abbreviations (PC1, CCA, RDA for ordination methods), weak crypto flags are biological substitution matrices (BLOSUM62 for protein alignments), and URLs are official documentation links. No command injection, network exfiltration, or malicious patterns exist.

3
Files scanned
1,393
Lines analyzed
2
Review items
0
False positives ignored
Audited by: claude

Jan 17, 2026, 06:52 AM

Documentation-only skill with no executable code. All 133 static findings are false positives: detected backticks are markdown code delimiters, C2 keywords are scientific abbreviations (PC1, CCA, RDA for ordination methods), weak crypto flags are biological substitution matrices (BLOSUM62 for protein alignments), and URLs are official documentation links. No command injection, network exfiltration, or malicious patterns exist.

3
Files scanned
1,393
Lines analyzed
2
Review items
0
False positives ignored
Audited by: claude

Jan 12, 2026, 04:04 PM

This is a documentation-only skill with no executable code. All 125 static findings are false positives: detected backticks are markdown code delimiters, C2 keywords are scientific abbreviations (PC1, CCA), weak crypto flags are biological substitution matrices (BLOSUM62), and URLs are official documentation links.

2
Files scanned
1,187
Lines analyzed
1
Review items
0
False positives ignored

Risk Factors

Audited by: claude

Jan 5, 2026, 04:18 PM

This is a documentation-only skill containing no executable code. The skill provides guidance on using the scikit-bio Python library for bioinformatics analysis. All files are markdown documentation and JSON metadata with code examples demonstrating legitimate biological data analysis operations.

5
Files scanned
1,210
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude