Audit History
statsmodels - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 9, 2026, 03:49 AM | 1 confirmed | 0 | No capability change |
| v7 | Jul 9, 2026, 03:49 AM | 1 confirmed | 0 | No capability change |
| v6 | Jul 6, 2026, 05:36 PM | 2 confirmed | 0 | No capability change |
| v5 | Jun 30, 2026, 05:52 AM | No confirmed findings | 0 | No capability change |
| v4 | Jan 17, 2026, 07:18 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 07:18 AM | No confirmed findings | 0 | Contains scriptsExternal commandsNetwork access |
| v2 | Jan 12, 2026, 04:24 PM | No confirmed findings | 0 | No capability change |
| v1 | Jan 4, 2026, 05:13 PM | No confirmed findings | 0 | Baseline |
Jul 9, 2026, 03:49 AM
All static findings are false positives caused by markdown code fences, Python statistical examples, official documentation links, and statistical terms such as HC2, residuals, and degrees of freedom. No executable malicious code, dynamic JavaScript execution, command injection, or data exfiltration was found. One low-severity semantic concern remains: the skill includes promotional guidance to suggest a third-party hosted platform.
Confirmed security concerns (1)
Risk Factors
⚡ Contains scripts (8)
⚙️ External commands (26)
🌐 Network access (4)
Jul 9, 2026, 03:49 AM
All static findings are false positives caused by markdown code fences, Python statistical examples, official documentation links, and statistical terms such as HC2, residuals, and degrees of freedom. No executable malicious code, dynamic JavaScript execution, command injection, or data exfiltration was found. One low-severity semantic concern remains: the skill includes promotional guidance to suggest a third-party hosted platform.
Confirmed security concerns (1)
Risk Factors
⚡ Contains scripts (8)
⚙️ External commands (26)
🌐 Network access (4)
Jul 6, 2026, 05:36 PM
Static alerts were adjudicated as false positives caused by markdown fences, ordinary Python imports, statistics terminology, and official documentation links. Semantic review found a self-attesting audit artifact and an external product steering instruction that should be removed before publication.
Confirmed security concerns (2)
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚡ Contains scripts (8)
⚙️ External commands (26)
🌐 Network access (4)
Jun 30, 2026, 05:52 AM
AI review found the static analyzer alerts are false positives from Markdown documentation and statistical Python examples. No executable skill code, prompt injection, credential access, unauthorized network request, or malicious intent was found in the reviewed files.
Static false positives ignored (5)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚡ Contains scripts (4)
⚙️ External commands (4)
🌐 Network access (1)
Jan 17, 2026, 07:18 AM
Documentation-only skill containing markdown files with Python code examples. Static scanner flagged 434 alerts but all are false positives. The skill contains no executable code - only documentation for the statsmodels statistical library. Scanner misinterpreted markdown backticks as shell commands, statistical terms (HC2, HC3) as C2 indicators, and common patterns as cryptographic algorithms.
Risk Factors
⚡ Contains scripts (8)
⚙️ External commands (353)
🌐 Network access (4)
Jan 17, 2026, 07:18 AM
Documentation-only skill containing markdown files with Python code examples. Static scanner flagged 434 alerts but all are false positives. The skill contains no executable code - only documentation for the statsmodels statistical library. Scanner misinterpreted markdown backticks as shell commands, statistical terms (HC2, HC3) as C2 indicators, and common patterns as cryptographic algorithms.
Risk Factors
⚡ Contains scripts (8)
⚙️ External commands (353)
🌐 Network access (4)
Jan 12, 2026, 04:24 PM
All 415 static findings are false positives. The scanned files are markdown documentation containing Python code examples. The analyzer misinterpreted markdown code block delimiters (```python) as shell commands, statistical function names as cryptographic algorithms, and common English words as C2 keywords. No malicious code exists in this skill.
Jan 4, 2026, 05:13 PM
Pure documentation skill with no executable code. Contains instructional markdown files teaching statsmodels usage. No network calls, file access, or code execution capabilities.