Histórico de Auditoria
esm - 5 auditorias
Versão da auditoria 5
Mais recente SeguroJan 21, 2026, 05:24 PM
All 368 static findings are false positives. The scanner incorrectly flagged markdown documentation patterns. The skill provides documentation for legitimate protein language models from EvolutionaryScale. All code examples are standard scientific workflows for protein engineering. Python f-strings with underscores (protein masks), MD5 for cache keys, and ML terminology were misclassified as security issues.
Fatores de risco
⚡ Contém scripts (5)
🌐 Acesso à rede (21)
⚙️ Comandos externos (188)
📁 Acesso ao sistema de arquivos (13)
Versão da auditoria 4
Risco MédioJan 17, 2026, 07:02 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Fatores de risco
⚡ Contém scripts (4)
🌐 Acesso à rede (22)
⚙️ Comandos externos (188)
📁 Acesso ao sistema de arquivos (13)
Padrões Detectados
Versão da auditoria 3
Risco MédioJan 17, 2026, 07:02 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Fatores de risco
⚡ Contém scripts (4)
🌐 Acesso à rede (22)
⚙️ Comandos externos (188)
📁 Acesso ao sistema de arquivos (13)
Padrões Detectados
Versão da auditoria 2
Baixo RiscoJan 12, 2026, 04:38 PM
All 319 static findings are FALSE POSITIVES. The scanner misidentified markdown code formatting (backticks) as shell commands, HTTPS URLs as weak crypto, PyTorch's model.eval() as dynamic code execution, and standard file I/O as system reconnaissance. This is legitimate scientific documentation for a protein language model library.
Fatores de risco
🌐 Acesso à rede (1)
📁 Acesso ao sistema de arquivos (1)
Versão da auditoria 1
SeguroJan 4, 2026, 04:19 PM
This is a pure documentation skill containing only markdown files with API references and code examples for protein modeling. No executable code, scripts, file system access, or network calls are present in the skill itself. The network references in documentation describe how to use the Forge API, but the skill does not make network requests.