技能 fda-database 審計歷史
💊

審計歷史

fda-database - 4 審計

審計版本 4

最新 安全

Jan 17, 2026, 07:13 AM

This is a legitimate API wrapper for the FDA's public openFDA API (api.fda.gov). All static findings are false positives: the 'CRITICAL' heuristic flagged code execution + network + credential access as suspicious, but this is standard API client behavior for authenticating with a legitimate government API. MD5 is used for cache key generation, not cryptographic security. Documentation code blocks were misidentified as shell commands. All network requests go to the official FDA API endpoint with no exfiltration or credential theft patterns.

11
已掃描檔案
4,787
分析行數
3
發現項
claude
審計者
未發現安全問題

審計版本 3

安全

Jan 17, 2026, 07:13 AM

This is a legitimate API wrapper for the FDA's public openFDA API (api.fda.gov). All static findings are false positives: the 'CRITICAL' heuristic flagged code execution + network + credential access as suspicious, but this is standard API client behavior for authenticating with a legitimate government API. MD5 is used for cache key generation, not cryptographic security. Documentation code blocks were misidentified as shell commands. All network requests go to the official FDA API endpoint with no exfiltration or credential theft patterns.

11
已掃描檔案
4,787
分析行數
3
發現項
claude
審計者
未發現安全問題

審計版本 2

安全

Jan 12, 2026, 04:46 PM

The fda-database skill is a legitimate scientific research tool for querying FDA's public openFDA API. Static analysis flagged many false positives - the 'external_commands' are actually markdown code examples showing API usage patterns, not actual command execution. The API key usage is legitimate for accessing public FDA data with proper authentication. No malicious intent detected.

9
已掃描檔案
4,311
分析行數
2
發現項
claude
審計者
未發現安全問題

審計版本 1

安全

Jan 4, 2026, 04:22 PM

No credential access, environment harvesting, or exfiltration patterns found. Network calls target the documented openFDA API for expected data retrieval.

9
已掃描檔案
4,300
分析行數
1
發現項
claude
審計者
未發現安全問題

風險因素

🌐 網路存取 (1)