Histórico de Auditoria
treatment-plans - 4 auditorias
Versão da auditoria 4
Mais recente SeguroJan 17, 2026, 07:42 AM
All 512 static findings are FALSE POSITIVES. This is a legitimate medical treatment plan documentation skill. The static scanner incorrectly triggers on LaTeX package declarations (flagged as 'weak crypto'), medical terminology like 'system' (flagged as 'reconnaissance'), and markdown backticks (flagged as 'shell execution'). No malicious code, network access, credential handling, or exfiltration patterns exist. The skill only generates LaTeX templates and runs local validation scripts.
Fatores de risco
⚡ Contém scripts (3)
📁 Acesso ao sistema de arquivos (1)
Versão da auditoria 3
SeguroJan 17, 2026, 07:42 AM
All 512 static findings are FALSE POSITIVES. This is a legitimate medical treatment plan documentation skill. The static scanner incorrectly triggers on LaTeX package declarations (flagged as 'weak crypto'), medical terminology like 'system' (flagged as 'reconnaissance'), and markdown backticks (flagged as 'shell execution'). No malicious code, network access, credential handling, or exfiltration patterns exist. The skill only generates LaTeX templates and runs local validation scripts.
Fatores de risco
⚡ Contém scripts (3)
📁 Acesso ao sistema de arquivos (1)
Versão da auditoria 2
SeguroJan 12, 2026, 04:36 PM
All 499 static findings are FALSE POSITIVES. This is a legitimate medical documentation skill that generates LaTeX treatment plans. Static patterns triggered on medical terminology (assessment, monitoring), LaTeX package declarations, and markdown code fences. No malicious code, network access, credential handling, or exfiltration patterns found.
Fatores de risco
Versão da auditoria 1
Baixo RiscoJan 4, 2026, 05:28 PM
Legitimate medical documentation skill. Python scripts perform local file operations only - reading/writing treatment plan templates. No network calls, no credential access, no obfuscation. Scripts check completeness and validate LaTeX content against clinical standards. The only capabilities are local file I/O which is appropriate for template generation tools.