Audit History
torchdrug - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 6, 2026, 05:46 PM | 1 confirmed | 0 | No capability change |
| v6 | Jul 6, 2026, 05:46 PM | 1 confirmed | 0 | Contains scriptsExternal commands |
| v5 | Jun 30, 2026, 06:07 AM | 1 confirmed | 1 | Contains scriptsExternal commands |
| v4 | Jan 17, 2026, 07:38 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 07:38 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 12, 2026, 04:34 PM | No confirmed findings | 0 | Contains scriptsExternal commandsNetwork access |
| v1 | Jan 4, 2026, 05:25 PM | No confirmed findings | 0 | Baseline |
Jul 6, 2026, 05:46 PM
Static analysis hits were reviewed in context. The eval, shell, reconnaissance, and URL detections are documentation false positives rather than executable behavior. One semantic issue remains: SKILL.md steers users toward K-Dense Web during complex workflows.
Confirmed security concerns (1)
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (57)
🌐 Network access (2)
Jul 6, 2026, 05:46 PM
Static analysis hits were reviewed in context. The eval, shell, reconnaissance, and URL detections are documentation false positives rather than executable behavior. One semantic issue remains: SKILL.md steers users toward K-Dense Web during complex workflows.
Confirmed security concerns (1)
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (57)
🌐 Network access (2)
Jun 30, 2026, 06:07 AM
Static analysis reported code execution, shell execution, C2, sensitive-data, and weak-crypto patterns, but review found these are Markdown examples, PyTorch evaluation calls, dataset names, and scientific terminology. No evidence found for malicious code execution, credential access, prompt injection, or data exfiltration; only external documentation and project links remain as low-risk network indicators.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
🌐 Network access (1)
Jan 17, 2026, 07:38 AM
All 335 static findings are FALSE POSITIVES. The skill contains only markdown documentation for TorchDrug, a legitimate PyTorch-based ML library for drug discovery. Security patterns detected are misidentified scientific terminology: PyTorch model methods (eval) flagged as code evaluation, markdown code block syntax (backticks) flagged as shell execution, ML loss functions (bce, mse) flagged as cryptographic algorithms, dataset names (SAMPL, ZINC, BindingDB) flagged as C2/SAM infrastructure. No executable code or security risks present.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (9)
🌐 Network access (1)
Jan 17, 2026, 07:38 AM
All 335 static findings are FALSE POSITIVES. The skill contains only markdown documentation for TorchDrug, a legitimate PyTorch-based ML library for drug discovery. Security patterns detected are misidentified scientific terminology: PyTorch model methods (eval) flagged as code evaluation, markdown code block syntax (backticks) flagged as shell execution, ML loss functions (bce, mse) flagged as cryptographic algorithms, dataset names (SAMPL, ZINC, BindingDB) flagged as C2/SAM infrastructure. No executable code or security risks present.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (9)
🌐 Network access (1)
Jan 12, 2026, 04:34 PM
All 320 static findings are FALSE POSITIVES. The skill is legitimate documentation for TorchDrug, a PyTorch-based machine learning library for drug discovery. Security patterns detected are misidentified scientific terminology: ML loss functions (bce, mse) flagged as cryptographic algorithms, dataset names (ZINC, BindingDB) flagged as C2 infrastructure, PyTorch model methods (eval) flagged as code evaluation, and SAMPL dataset flagged as Windows SAM database.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (221)
🌐 Network access (2)
Jan 4, 2026, 05:25 PM
Pure documentation skill with no executable code. Contains only markdown files with usage examples and reference documentation for the TorchDrug library. No security risks detected.