Audit-Verlauf
pathml - 4 Audits
Audit-Version 4
Neueste SicherJan 17, 2026, 07:03 AM
PathML is a legitimate open-source computational pathology toolkit. All 554 static findings are false positives - the scanner detected patterns in markdown documentation (code examples) rather than actual executable code. The 'eval()' detections are PyTorch's model.eval() method, not dynamic code execution. Shell command patterns are documentation examples for batch processing workflows. No malicious intent, data exfiltration, or security vulnerabilities confirmed.
Risikofaktoren
⚡ Enthält Skripte (2)
⚙️ Externe Befehle (2)
🌐 Netzwerkzugriff (1)
📁 Dateisystemzugriff (1)
Audit-Version 3
SicherJan 17, 2026, 07:03 AM
PathML is a legitimate open-source computational pathology toolkit. All 554 static findings are false positives - the scanner detected patterns in markdown documentation (code examples) rather than actual executable code. The 'eval()' detections are PyTorch's model.eval() method, not dynamic code execution. Shell command patterns are documentation examples for batch processing workflows. No malicious intent, data exfiltration, or security vulnerabilities confirmed.
Risikofaktoren
⚡ Enthält Skripte (2)
⚙️ Externe Befehle (2)
🌐 Netzwerkzugriff (1)
📁 Dateisystemzugriff (1)
Audit-Version 2
SicherJan 12, 2026, 04:20 PM
PathML is a legitimate scientific computing library for pathology image analysis. Static findings are false positives - the code uses standard scientific computing patterns (eval for configuration, backticks for documentation examples, memory mapping for large images). No malicious intent detected.
Risikofaktoren
⚡ Enthält Skripte (1)
⚙️ Externe Befehle (1)
🌐 Netzwerkzugriff (1)
📁 Dateisystemzugriff (1)
Audit-Version 1
SicherJan 4, 2026, 05:25 PM
This skill contains only documentation files with no executable code. All content consists of markdown reference guides and metadata. The example code snippets are purely illustrative and do not execute. No malicious patterns, data exfiltration, credential theft, or code execution capabilities are present.