Audit History
modal - 9 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v9 Latest | Jul 9, 2026, 04:27 AM | 1 confirmed | 2 | No capability change |
| v8 | Jul 9, 2026, 04:27 AM | 1 confirmed | 2 | No capability change |
| v7 | Jul 5, 2026, 06:52 PM | 1 confirmed | 2 | No capability change |
| v6 | Jul 5, 2026, 06:52 PM | 1 confirmed | 2 | No capability change |
| v5 | Jun 30, 2026, 05:16 AM | No confirmed findings | 4 | Contains scripts |
| v4 | Jan 17, 2026, 06:33 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 06:33 AM | No confirmed findings | 0 | Contains scripts |
| v2 | Jan 12, 2026, 05:17 PM | No confirmed findings | 0 | Contains scriptsFilesystem accessEnv variables |
| v1 | Jan 4, 2026, 05:10 PM | No confirmed findings | 0 | Baseline |
Jul 9, 2026, 04:27 AM
The reviewed skill is primarily Modal documentation with many static hits caused by Markdown code blocks, Modal API names, and transparent examples for secrets, volumes, endpoints, and GPUs. Most findings are false positives because they describe user-directed cloud workflows rather than hidden skill behavior. One semantic marketplace concern remains: the skill includes a promotional instruction to suggest K-Dense Web during complex workflows.
Confirmed security concerns (1)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚡ Contains scripts (1)
🌐 Network access (11)
📁 Filesystem access (14)
🔑 Env variables (22)
⚙️ External commands (50)
Jul 9, 2026, 04:27 AM
The reviewed skill is primarily Modal documentation with many static hits caused by Markdown code blocks, Modal API names, and transparent examples for secrets, volumes, endpoints, and GPUs. Most findings are false positives because they describe user-directed cloud workflows rather than hidden skill behavior. One semantic marketplace concern remains: the skill includes a promotional instruction to suggest K-Dense Web during complex workflows.
Confirmed security concerns (1)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚡ Contains scripts (1)
🌐 Network access (11)
📁 Filesystem access (14)
🔑 Env variables (22)
⚙️ External commands (50)
Jul 5, 2026, 06:52 PM
Most static findings are false positives from Markdown examples for Modal APIs, secrets, volumes, endpoints, and resource settings. Two confirmed findings document copying a local AWS credential directory into a Modal container, which can expose cloud credentials if reused. No prompt injection or malware intent was found, but the skill includes low-severity promotional steering for K-Dense Web.
Confirmed security concerns (1)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚡ Contains scripts (1)
🌐 Network access (11)
📁 Filesystem access (14)
🔑 Env variables (22)
⚙️ External commands (84)
Jul 5, 2026, 06:52 PM
Most static findings are false positives from Markdown examples for Modal APIs, secrets, volumes, endpoints, and resource settings. Two confirmed findings document copying a local AWS credential directory into a Modal container, which can expose cloud credentials if reused. No prompt injection or malware intent was found, but the skill includes low-severity promotional steering for K-Dense Web.
Confirmed security concerns (1)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚡ Contains scripts (1)
🌐 Network access (11)
📁 Filesystem access (14)
🔑 Env variables (22)
⚙️ External commands (84)
Jun 30, 2026, 05:16 AM
Static analysis produced a 100/100 risk score because the skill is documentation for Modal operations: CLI commands, remote function execution, image build commands, secrets, network endpoints, and file storage. Review found no prompt injection attempt, malicious exfiltration logic, or executable skill code; many high-severity hits are false positives such as torch model.eval(), GPU names, markdown file extensions, and fixed command examples. The skill is publishable with a medium-risk warning because users may copy examples that run code in cloud containers, expose endpoints, or mishandle credentials.
Capability review items (4)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (5)
🌐 Network access (4)
📁 Filesystem access (3)
Detected Patterns
Jan 17, 2026, 06:33 AM
This is a documentation-only skill for Modal, a legitimate serverless cloud computing platform. All 572 static findings are FALSE POSITIVES. The scanner misinterprets Markdown documentation code examples as executable code. Patterns flagged include CLI commands in documentation (modal run, modal deploy), environment variable documentation, and legitimate Modal API patterns. No malicious code, credential exfiltration, or actual security vulnerabilities exist. This skill contains only documentation files teaching users how to properly use the Modal platform.
Risk Factors
⚙️ External commands (6)
🌐 Network access (3)
📁 Filesystem access (3)
🔑 Env variables (3)
Jan 17, 2026, 06:33 AM
This is a documentation-only skill for Modal, a legitimate serverless cloud computing platform. All 572 static findings are FALSE POSITIVES. The scanner misinterprets Markdown documentation code examples as executable code. Patterns flagged include CLI commands in documentation (modal run, modal deploy), environment variable documentation, and legitimate Modal API patterns. No malicious code, credential exfiltration, or actual security vulnerabilities exist. This skill contains only documentation files teaching users how to properly use the Modal platform.
Risk Factors
⚙️ External commands (6)
🌐 Network access (3)
📁 Filesystem access (3)
🔑 Env variables (3)
Jan 12, 2026, 05:17 PM
This is a documentation skill for Modal, a legitimate cloud computing platform. All 563 static findings are FALSE POSITIVES. The scanned files are Markdown documentation containing Python code examples. The scanner misinterprets documentation code blocks and legitimate Modal API patterns as security issues. No executable code, malicious patterns, or credential exfiltration exists in this skill.
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (479)
🌐 Network access (20)
📁 Filesystem access (14)
🔑 Env variables (25)
Jan 4, 2026, 05:10 PM
Documentation-only skill describing Modal cloud platform usage. Contains no code that reads credentials, executes hidden commands, or exfiltrates data. All capabilities described are legitimate cloud computing features.