審計歷史
matchms - 4 審計
審計版本 4
最新 安全Jan 17, 2026, 06:24 AM
All 268 static findings are false positives. The analyzer incorrectly flagged markdown code blocks (backticks) as shell execution, InChIKey descriptions as cryptographic algorithms, scientific database URLs as network reconnaissance, and legitimate Python code examples as malicious patterns. Matchms is a legitimate open-source mass spectrometry library for metabolomics research.
風險因素
🌐 網路存取 (3)
📁 檔案系統存取 (1)
審計版本 3
安全Jan 17, 2026, 06:24 AM
All 268 static findings are false positives. The analyzer incorrectly flagged markdown code blocks (backticks) as shell execution, InChIKey descriptions as cryptographic algorithms, scientific database URLs as network reconnaissance, and legitimate Python code examples as malicious patterns. Matchms is a legitimate open-source mass spectrometry library for metabolomics research.
風險因素
🌐 網路存取 (3)
📁 檔案系統存取 (1)
審計版本 2
安全Jan 12, 2026, 05:08 PM
The static analyzer incorrectly flagged documentation code blocks as security issues. All findings are false positives - the 'weak cryptographic algorithm' and 'external commands' alerts stem from markdown documentation containing code examples and legitimate URLs to scientific resources. No actual security risks were found.
風險因素
⚡ 包含腳本 (1)
⚙️ 外部命令 (1)
🌐 網路存取 (1)
審計版本 1
安全Jan 4, 2026, 04:58 PM
Documentation-only skill containing markdown guides and code examples for the matchms Python library. No executable code, no credential access, no network exfiltration. Pure prompt-based guidance.