Histórico de Auditoria
etetoolkit - 4 auditorias
Versão da auditoria 4
Mais recente SeguroJan 17, 2026, 07:05 AM
The skill is a legitimate scientific bioinformatics tool. All 434 static findings are false positives. The 'Ruby/shell backtick' detections are markdown code block delimiters, not command execution. 'External commands' flagged are documentation examples for package installation. 'Weak cryptographic' findings are misidentified scientific function names. The Python scripts (tree_operations.py, quick_visualize.py) contain standard tree manipulation utilities with no security risks.
Fatores de risco
📁 Acesso ao sistema de arquivos (1)
⚙️ Comandos externos (2)
Versão da auditoria 3
SeguroJan 17, 2026, 07:05 AM
The skill is a legitimate scientific bioinformatics tool. All 434 static findings are false positives. The 'Ruby/shell backtick' detections are markdown code block delimiters, not command execution. 'External commands' flagged are documentation examples for package installation. 'Weak cryptographic' findings are misidentified scientific function names. The Python scripts (tree_operations.py, quick_visualize.py) contain standard tree manipulation utilities with no security risks.
Fatores de risco
📁 Acesso ao sistema de arquivos (1)
⚙️ Comandos externos (2)
Versão da auditoria 2
SeguroJan 12, 2026, 04:40 PM
The static findings are false positives from documentation examples. The code contains legitimate scientific computing operations with no actual security risks. All 'external_commands' are documentation examples showing shell commands for package installation, and 'weak cryptographic' findings are misidentified scientific functions.
Fatores de risco
⚙️ Comandos externos (1)
📁 Acesso ao sistema de arquivos (1)
Versão da auditoria 1
Baixo RiscoJan 4, 2026, 04:20 PM
The skill contains legitimate bioinformatics scripts for phylogenetic tree analysis. No malicious patterns detected. Scripts only process local tree files and generate visualizations without network access or credential harvesting.