技能 brenda-database 審計歷史
enzyme

審計歷史

brenda-database - 4 審計

審計版本 4

最新 低風險

Jan 17, 2026, 05:57 AM

The brenda-database skill is a legitimate scientific tool for accessing enzyme data from the BRENDA database. All 436 static findings are false positives triggered by documentation formatting (backtick characters for code blocks), legitimate BRENDA API authentication (SHA-256 password hashing), and biochemical terminology (NAD+, ATP as cofactors, not C2 commands). The codebase performs authorized SOAP API queries to a public scientific database and exports research data. No malicious behavior, data exfiltration, or unauthorized access patterns were found.

7
已掃描檔案
4,388
分析行數
3
發現項
claude
審計者
未發現安全問題

風險因素

審計版本 3

低風險

Jan 17, 2026, 05:57 AM

The brenda-database skill is a legitimate scientific tool for accessing enzyme data from the BRENDA database. All 436 static findings are false positives triggered by documentation formatting (backtick characters for code blocks), legitimate BRENDA API authentication (SHA-256 password hashing), and biochemical terminology (NAD+, ATP as cofactors, not C2 commands). The codebase performs authorized SOAP API queries to a public scientific database and exports research data. No malicious behavior, data exfiltration, or unauthorized access patterns were found.

7
已掃描檔案
4,388
分析行數
3
發現項
claude
審計者
未發現安全問題

風險因素

審計版本 2

低風險

Jan 12, 2026, 04:27 PM

This is a legitimate scientific tool for querying the BRENDA enzyme database. Static findings are false positives caused by the analyzer misidentifying code examples as shell commands, biochemical abbreviations as C2 keywords, and proper credential handling as sensitive data access. All network requests go to the official BRENDA API. No evidence of malicious intent, data exfiltration, or command-and-control behavior.

5
已掃描檔案
3,925
分析行數
3
發現項
claude
審計者
未發現安全問題

風險因素

審計版本 1

低風險

Jan 4, 2026, 04:45 PM

The skill provides legitimate access to the BRENDA enzyme database via SOAP API. Network calls are limited to the official BRENDA endpoint. Environment variable access is required for authenticated API access. File writes are confined to data exports and visualization outputs within user-specified directories. No obfuscation, external command execution, or persistence mechanisms detected.

8
已掃描檔案
4,210
分析行數
4
發現項
claude
審計者
未發現安全問題