Audit-Verlauf
esm - 5 Audits
Audit-Version 5
Neueste SicherJan 21, 2026, 05:24 PM
All 368 static findings are false positives. The scanner incorrectly flagged markdown documentation patterns. The skill provides documentation for legitimate protein language models from EvolutionaryScale. All code examples are standard scientific workflows for protein engineering. Python f-strings with underscores (protein masks), MD5 for cache keys, and ML terminology were misclassified as security issues.
Risikofaktoren
⚡ Enthält Skripte (5)
🌐 Netzwerkzugriff (21)
⚙️ Externe Befehle (188)
📁 Dateisystemzugriff (13)
Audit-Version 4
Mittleres RisikoJan 17, 2026, 07:02 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risikofaktoren
⚡ Enthält Skripte (4)
🌐 Netzwerkzugriff (22)
⚙️ Externe Befehle (188)
📁 Dateisystemzugriff (13)
Erkannte Muster
Audit-Version 3
Mittleres RisikoJan 17, 2026, 07:02 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risikofaktoren
⚡ Enthält Skripte (4)
🌐 Netzwerkzugriff (22)
⚙️ Externe Befehle (188)
📁 Dateisystemzugriff (13)
Erkannte Muster
Audit-Version 2
Niedriges RisikoJan 12, 2026, 04:38 PM
All 319 static findings are FALSE POSITIVES. The scanner misidentified markdown code formatting (backticks) as shell commands, HTTPS URLs as weak crypto, PyTorch's model.eval() as dynamic code execution, and standard file I/O as system reconnaissance. This is legitimate scientific documentation for a protein language model library.
Risikofaktoren
🌐 Netzwerkzugriff (1)
📁 Dateisystemzugriff (1)
Audit-Version 1
SicherJan 4, 2026, 04:19 PM
This is a pure documentation skill containing only markdown files with API references and code examples for protein modeling. No executable code, scripts, file system access, or network calls are present in the skill itself. The network references in documentation describe how to use the Forge API, but the skill does not make network requests.