Audit-Verlauf
scikit-learn - 9 Audits
Versionsvergleich
Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.
| Version | Datum | Ergebnis | Prüfelemente | Änderung ggü. vorheriger |
|---|---|---|---|---|
| v9 Neueste | 2026年7月23日 15:00 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v8 | 2026年7月8日 07:23 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v7 | 2026年7月6日 09:53 | 1 bestätigt | 0 | Keine Änderung der Fähigkeiten |
| v6 | 2026年6月29日 15:02 | 2 bestätigt | 0 | DateisystemzugriffNetzwerkzugriff |
| v5 | 2026年1月17日 01:23 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v4 | 2026年1月17日 01:23 | Keine bestätigten Befunde | 0 | Externe Befehle |
| v3 | 2026年1月7日 00:51 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v2 | 2026年1月7日 00:51 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v1 | 2026年1月7日 00:51 | Keine bestätigten Befunde | 0 | Ausgangsbasis |
2026年7月23日 15:00
All 89 static findings are false positives caused by Python import formatting, machine learning terminology, documented local caching, Markdown backticks, and official documentation links. No prompt injection, credential access, exfiltration, unsafe dynamic execution, or hostile intent was found.
Risikofaktoren
⚡ Enthält Skripte (7)
📁 Dateisystemzugriff (5)
⚙️ Externe Befehle (50)
🌐 Netzwerkzugriff (4)
2026年7月8日 07:23
All 89 static alerts were reviewed and adjudicated as false positives. The alerts come from Markdown examples, static scikit-learn imports, local model and cache examples, official documentation links, and explicit local demo commands. No prompt injection, secret exfiltration, hidden network calls, or malicious intent was found.
Risikofaktoren
⚡ Enthält Skripte (7)
📁 Dateisystemzugriff (5)
⚙️ Externe Befehle (55)
🌐 Netzwerkzugriff (4)
2026年7月6日 09:53
Static findings were reviewed in context; the import, grid search, temp cache, URL, and Markdown backtick matches are false positives from normal scikit-learn documentation and examples. No prompt injection or data-exfiltration intent was found. The remaining content-level issue is unsafe pickle loading guidance without a trusted-source warning.
Bestätigte Sicherheitsbedenken (1)
Risikofaktoren
⚡ Enthält Skripte (7)
📁 Dateisystemzugriff (5)
⚙️ Externe Befehle (55)
🌐 Netzwerkzugriff (4)
2026年6月29日 15:02
AI review dismisses the critical heuristic and most static findings as false positives caused by markdown code fences, normal Python imports, ML terminology, and official documentation links. No prompt injection evidence was found in targeted review. The remaining real concerns are low-risk local artifact writes and serialized model loading examples that require trusted inputs.
Bestätigte Sicherheitsbedenken (2)
Statische falsch positive Treffer ignoriert (3)
Diese statischen Treffer wurden durch semantische Prüfung verworfen oder entsprachen reinen Schema-Tokens; daher werden sie aus Transparenzgründen angezeigt, beeinflussen jedoch nicht die Qualitätsbewertung.
Risikofaktoren
⚡ Enthält Skripte (2)
⚙️ Externe Befehle (2)
📁 Dateisystemzugriff (4)
🌐 Netzwerkzugriff (2)
Erkannte Muster
2026年1月17日 01:23
All 566 static findings are FALSE POSITIVES. The static analyzer misidentified markdown documentation syntax (backticks for code formatting) as shell commands, Python import examples as dynamic imports, and 'PC2' (Principal Component 2) as C2 command-and-control keywords. This is a pure documentation/reference skill containing legitimate scikit-learn ML examples with no network calls, credential access, or file exfiltration capabilities.
Risikofaktoren
⚡ Enthält Skripte (2)
⚙️ Externe Befehle (2)
2026年1月17日 01:23
All 566 static findings are FALSE POSITIVES. The static analyzer misidentified markdown documentation syntax (backticks for code formatting) as shell commands, Python import examples as dynamic imports, and 'PC2' (Principal Component 2) as C2 command-and-control keywords. This is a pure documentation/reference skill containing legitimate scikit-learn ML examples with no network calls, credential access, or file exfiltration capabilities.
Risikofaktoren
⚡ Enthält Skripte (2)
⚙️ Externe Befehle (2)
2026年1月7日 00:51
This is a pure documentation and reference skill containing legitimate scikit-learn machine learning examples. The two Python scripts are standard ML workflows for classification and clustering. No network calls, no credential access, no shell commands, no file exfiltration capabilities. All capabilities match the stated purpose of providing ML guidance.
Risikofaktoren
⚡ Enthält Skripte (2)
2026年1月7日 00:51
This is a pure documentation and reference skill containing legitimate scikit-learn machine learning examples. The two Python scripts are standard ML workflows for classification and clustering. No network calls, no credential access, no shell commands, no file exfiltration capabilities. All capabilities match the stated purpose of providing ML guidance.
Risikofaktoren
⚡ Enthält Skripte (2)
2026年1月7日 00:51
This is a pure documentation and reference skill containing legitimate scikit-learn machine learning examples. The two Python scripts are standard ML workflows for classification and clustering. No network calls, no credential access, no shell commands, no file exfiltration capabilities. All capabilities match the stated purpose of providing ML guidance.