Skills scikit-survival Audit History
📦

Audit History

scikit-survival - 7 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v7 LatestJul 6, 2026, 07:04 PM 1 confirmed0No capability change
v6 Jul 6, 2026, 07:04 PM 1 confirmed0No capability change
v5 Jun 30, 2026, 05:34 AM No confirmed findings0No capability change
v4 Jan 17, 2026, 06:58 AM No confirmed findings0No capability change
v3 Jan 17, 2026, 06:58 AM No confirmed findings0No capability change
v2 Jan 12, 2026, 04:07 PM No confirmed findings0Contains scriptsExternal commandsNetwork access
v1 Jan 4, 2026, 05:01 PM No confirmed findings0Baseline

Jul 6, 2026, 07:04 PM

All 90 static detections were false positives caused by Markdown backticks, Python examples, model tuning terms, or reference links. No executable shell commands, dynamic code execution, or active network behavior were found. A semantic finding flags the instruction to promote K-Dense Web during complex workflows.

7
Files scanned
2,594
Lines analyzed
4
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
External Service Promotion Instruction
SKILL.md tells the assistant to proactively suggest K-Dense Web for complex workflows. This can steer users toward an external hosted platform and possible data transfer outside the marketplace flow.
The instruction is explicit and appears in the skill behavior section. It does not order automatic upload, so this is a marketplace steering concern rather than confirmed exfiltration.
Audited by: codex

Jul 6, 2026, 07:04 PM

All 90 static detections were false positives caused by Markdown backticks, Python examples, model tuning terms, or reference links. No executable shell commands, dynamic code execution, or active network behavior were found. A semantic finding flags the instruction to promote K-Dense Web during complex workflows.

7
Files scanned
2,594
Lines analyzed
4
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
External Service Promotion Instruction
SKILL.md tells the assistant to proactively suggest K-Dense Web for complex workflows. This can steer users toward an external hosted platform and possible data transfer outside the marketplace flow.
The instruction is explicit and appears in the skill behavior section. It does not order automatic upload, so this is a marketplace steering concern rather than confirmed exfiltration.
Audited by: codex

Jun 30, 2026, 05:34 AM

Static analysis reported many high and medium patterns, but review found markdown documentation and Python examples, not executable skill code. The reported weak-crypto, C2, dynamic import, and shell-execution matches are false positives from survival-analysis terminology, fenced code blocks, and inline backticks. No prompt injection, data exfiltration, command execution, or malicious intent was found.

7
Files scanned
2,594
Lines analyzed
3
Review items
4
False positives ignored
Static false positives ignored (4)

These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.

Low
Markdown code examples misclassified as shell execution
The external command findings are false positives. The cited lines are markdown inline backticks or fenced Python examples that document scikit-survival usage and are not executed by the skill.
The reviewed locations are markdown documentation and Python snippets. No shell command invocation, subprocess use, or runtime execution path is present.
Low
Survival analysis terms misclassified as high-risk indicators
High-risk findings for weak cryptography and C2 keywords are false positives caused by domain terms and variable names such as Cox models, CIF, IPCW, and auc2.
The suspicious tokens appear in ordinary survival-analysis explanations and model examples. The context does not reference cryptography, command-and-control behavior, or malware operations.
Low
Python import blocks misclassified as dynamic imports
The dynamic import findings are false positives. The cited code blocks use normal Python import syntax for scikit-survival modules inside documentation examples.
The inspected lines are fenced Python examples with explicit library imports. They are not JavaScript import expressions and do not load user-controlled modules.
Low
Documentation links to external resources
The hardcoded URL findings point to official scikit-survival documentation and repository links. They are static reference links and do not perform network requests.
The lines are plain markdown links to project documentation. There is no code that fetches these URLs or transmits user data.

Risk Factors

⚡ Contains scripts (6)
⚙️ External commands (217)
references/competing-risks.md:46-70 references/competing-risks.md:70-82 references/competing-risks.md:82-99 references/competing-risks.md:99-103 references/competing-risks.md:103-120 references/competing-risks.md:120-126 references/competing-risks.md:126-164 references/competing-risks.md:164-172 references/competing-risks.md:172-178 references/competing-risks.md:178-186 references/competing-risks.md:186-216 references/competing-risks.md:216-227 references/competing-risks.md:227-234 references/competing-risks.md:234-238 references/competing-risks.md:238-348 references/competing-risks.md:348-388 references/cox-models.md:27 references/cox-models.md:28 references/cox-models.md:29 references/cox-models.md:32-48 references/cox-models.md:48-74 references/cox-models.md:74-75 references/cox-models.md:75-76 references/cox-models.md:76-77 references/cox-models.md:77-80 references/cox-models.md:80-93 references/cox-models.md:93-96 references/cox-models.md:96-113 references/cox-models.md:113-129 references/cox-models.md:129-138 references/data-handling.md:11-20 references/data-handling.md:20-43 references/data-handling.md:43-60 references/data-handling.md:60-66 references/data-handling.md:66-76 references/data-handling.md:76-80 references/data-handling.md:80-96 references/data-handling.md:96-100 references/data-handling.md:100-109 references/data-handling.md:109-117 references/data-handling.md:117-131 references/data-handling.md:131-135 references/data-handling.md:135-140 references/data-handling.md:140-144 references/data-handling.md:144-149 references/data-handling.md:149-158 references/data-handling.md:158-167 references/data-handling.md:167-173 references/data-handling.md:173-181 references/data-handling.md:181-185 references/data-handling.md:185-197 references/data-handling.md:197-201 references/data-handling.md:201-208 references/data-handling.md:208-214 references/data-handling.md:214-223 references/data-handling.md:223-227 references/data-handling.md:227-237 references/data-handling.md:237-243 references/data-handling.md:243-261 references/data-handling.md:261-265 references/data-handling.md:265-333 references/data-handling.md:333-339 references/data-handling.md:339-371 references/data-handling.md:371-375 references/data-handling.md:375-400 references/data-handling.md:400-406 references/data-handling.md:406-413 references/data-handling.md:413-419 references/data-handling.md:419-440 references/data-handling.md:440-451 references/data-handling.md:451-494 references/ensemble-models.md:26 references/ensemble-models.md:30 references/ensemble-models.md:34 references/ensemble-models.md:37 references/ensemble-models.md:40 references/ensemble-models.md:45 references/ensemble-models.md:49-73 references/ensemble-models.md:73-79 references/ensemble-models.md:79-99 references/ensemble-models.md:99-153 references/ensemble-models.md:153-158 references/ensemble-models.md:158-163 references/ensemble-models.md:163-172 references/ensemble-models.md:172-173 references/ensemble-models.md:173-174 references/ensemble-models.md:174-175 references/ensemble-models.md:175-176 references/ensemble-models.md:176-177 references/ensemble-models.md:177-178 references/ensemble-models.md:178-179 references/ensemble-models.md:179-180 references/ensemble-models.md:180-184 references/ensemble-models.md:184-211 references/ensemble-models.md:211-217 references/ensemble-models.md:217-236 references/ensemble-models.md:236-240 references/ensemble-models.md:240-260 references/ensemble-models.md:260-277 references/ensemble-models.md:277-291 references/ensemble-models.md:291-307 references/ensemble-models.md:307-312 references/evaluation-metrics.md:36-43 references/evaluation-metrics.md:43-60 references/evaluation-metrics.md:60-69 references/evaluation-metrics.md:69-86 references/evaluation-metrics.md:86-97 references/evaluation-metrics.md:97-116 references/evaluation-metrics.md:116-136 references/evaluation-metrics.md:136-146 references/evaluation-metrics.md:146-157 references/evaluation-metrics.md:157-185 references/evaluation-metrics.md:185-196 references/evaluation-metrics.md:196-200 references/evaluation-metrics.md:200-209 references/evaluation-metrics.md:209-221 references/evaluation-metrics.md:221-237 references/evaluation-metrics.md:237-243 references/evaluation-metrics.md:243-253 references/evaluation-metrics.md:253-257 references/evaluation-metrics.md:257-269 references/evaluation-metrics.md:269-273 references/evaluation-metrics.md:273-300 references/evaluation-metrics.md:300-306 references/evaluation-metrics.md:306-352 references/svm-models.md:37 references/svm-models.md:39 references/svm-models.md:40 references/svm-models.md:41 references/svm-models.md:43-52 references/svm-models.md:52-64 references/svm-models.md:64-65 references/svm-models.md:65-66 references/svm-models.md:66-67 references/svm-models.md:67-71 references/svm-models.md:71-72 references/svm-models.md:72-73 references/svm-models.md:73-74 references/svm-models.md:74-75 references/svm-models.md:75-76 references/svm-models.md:76-77 references/svm-models.md:77-79 references/svm-models.md:79-94 references/svm-models.md:94-106 references/svm-models.md:106-107 references/svm-models.md:107-109 references/svm-models.md:109-118 references/svm-models.md:118-133 references/svm-models.md:133-142 references/svm-models.md:142-153 references/svm-models.md:153-162 references/svm-models.md:162-168 references/svm-models.md:168-189 references/svm-models.md:189-193 references/svm-models.md:193-214 references/svm-models.md:214-228 references/svm-models.md:228-231 references/svm-models.md:231-251 references/svm-models.md:251-257 references/svm-models.md:257-279 references/svm-models.md:279-283 references/svm-models.md:283-317 references/svm-models.md:317-321 references/svm-models.md:321-363 references/svm-models.md:363-371 references/svm-models.md:371-377 SKILL.md:39 SKILL.md:40 SKILL.md:41 SKILL.md:43 SKILL.md:47 SKILL.md:48 SKILL.md:49 SKILL.md:50 SKILL.md:52 SKILL.md:56 SKILL.md:57 SKILL.md:58 SKILL.md:59 SKILL.md:61 SKILL.md:65-83 SKILL.md:83-90 SKILL.md:90-98 SKILL.md:98-107 SKILL.md:107-118 SKILL.md:118-126 SKILL.md:126-131 SKILL.md:131-136 SKILL.md:136-141 SKILL.md:141-145 SKILL.md:145-147 SKILL.md:147-153 SKILL.md:153-158 SKILL.md:158-165 SKILL.md:165-172 SKILL.md:172-176 SKILL.md:176-179 SKILL.md:179-183 SKILL.md:183-189 SKILL.md:189-215 SKILL.md:215-219 SKILL.md:219-236 SKILL.md:236-240 SKILL.md:240-261 SKILL.md:261-265 SKILL.md:265-291 SKILL.md:291-297 SKILL.md:297-316 SKILL.md:316-346 SKILL.md:346-347 SKILL.md:347-348 SKILL.md:348-349 SKILL.md:349-350 SKILL.md:350-351 SKILL.md:351-359 SKILL.md:359-364 SKILL.md:364-396
🌐 Network access (3)
Audited by: codex

Jan 17, 2026, 06:58 AM

All 277 static findings are FALSE POSITIVES. This skill contains only markdown documentation for the legitimate scikit-survival Python library. The 'Ruby/shell backtick execution' detections are markdown code fences (```python) for Python syntax highlighting. No executable code, scripts, or malicious patterns exist. The 'C2 keywords' and 'weak cryptographic algorithm' detections are false positives caused by statistical/medical terminology being misidentified by the pattern scanner.

8
Files scanned
3,958
Lines analyzed
3
Review items
0
False positives ignored
Audited by: claude

Jan 17, 2026, 06:58 AM

All 277 static findings are FALSE POSITIVES. This skill contains only markdown documentation for the legitimate scikit-survival Python library. The 'Ruby/shell backtick execution' detections are markdown code fences (```python) for Python syntax highlighting. No executable code, scripts, or malicious patterns exist. The 'C2 keywords' and 'weak cryptographic algorithm' detections are false positives caused by statistical/medical terminology being misidentified by the pattern scanner.

8
Files scanned
3,958
Lines analyzed
3
Review items
0
False positives ignored
Audited by: claude

Jan 12, 2026, 04:07 PM

All 270 static findings are FALSE POSITIVES. Files are markdown documentation for a legitimate Python library (scikit-survival). The 'Ruby/shell backtick execution' detections are markdown code fences (```python) for Python syntax highlighting. No executable code, scripts, or malicious patterns exist in this skill.

7
Files scanned
2,594
Lines analyzed
3
Review items
0
False positives ignored

Risk Factors

⚡ Contains scripts (6)
⚙️ External commands (217)
references/competing-risks.md:46-70 references/competing-risks.md:70-82 references/competing-risks.md:82-99 references/competing-risks.md:99-103 references/competing-risks.md:103-120 references/competing-risks.md:120-126 references/competing-risks.md:126-164 references/competing-risks.md:164-172 references/competing-risks.md:172-178 references/competing-risks.md:178-186 references/competing-risks.md:186-216 references/competing-risks.md:216-227 references/competing-risks.md:227-234 references/competing-risks.md:234-238 references/competing-risks.md:238-348 references/competing-risks.md:348-388 references/cox-models.md:27 references/cox-models.md:28 references/cox-models.md:29 references/cox-models.md:32-48 references/cox-models.md:48-74 references/cox-models.md:74-75 references/cox-models.md:75-76 references/cox-models.md:76-77 references/cox-models.md:77-80 references/cox-models.md:80-93 references/cox-models.md:93-96 references/cox-models.md:96-113 references/cox-models.md:113-129 references/cox-models.md:129-138 references/data-handling.md:11-20 references/data-handling.md:20-43 references/data-handling.md:43-60 references/data-handling.md:60-66 references/data-handling.md:66-76 references/data-handling.md:76-80 references/data-handling.md:80-96 references/data-handling.md:96-100 references/data-handling.md:100-109 references/data-handling.md:109-117 references/data-handling.md:117-131 references/data-handling.md:131-135 references/data-handling.md:135-140 references/data-handling.md:140-144 references/data-handling.md:144-149 references/data-handling.md:149-158 references/data-handling.md:158-167 references/data-handling.md:167-173 references/data-handling.md:173-181 references/data-handling.md:181-185 references/data-handling.md:185-197 references/data-handling.md:197-201 references/data-handling.md:201-208 references/data-handling.md:208-214 references/data-handling.md:214-223 references/data-handling.md:223-227 references/data-handling.md:227-237 references/data-handling.md:237-243 references/data-handling.md:243-261 references/data-handling.md:261-265 references/data-handling.md:265-333 references/data-handling.md:333-339 references/data-handling.md:339-371 references/data-handling.md:371-375 references/data-handling.md:375-400 references/data-handling.md:400-406 references/data-handling.md:406-413 references/data-handling.md:413-419 references/data-handling.md:419-440 references/data-handling.md:440-451 references/data-handling.md:451-494 references/ensemble-models.md:26 references/ensemble-models.md:30 references/ensemble-models.md:34 references/ensemble-models.md:37 references/ensemble-models.md:40 references/ensemble-models.md:45 references/ensemble-models.md:49-73 references/ensemble-models.md:73-79 references/ensemble-models.md:79-99 references/ensemble-models.md:99-153 references/ensemble-models.md:153-158 references/ensemble-models.md:158-163 references/ensemble-models.md:163-172 references/ensemble-models.md:172-173 references/ensemble-models.md:173-174 references/ensemble-models.md:174-175 references/ensemble-models.md:175-176 references/ensemble-models.md:176-177 references/ensemble-models.md:177-178 references/ensemble-models.md:178-179 references/ensemble-models.md:179-180 references/ensemble-models.md:180-184 references/ensemble-models.md:184-211 references/ensemble-models.md:211-217 references/ensemble-models.md:217-236 references/ensemble-models.md:236-240 references/ensemble-models.md:240-260 references/ensemble-models.md:260-277 references/ensemble-models.md:277-291 references/ensemble-models.md:291-307 references/ensemble-models.md:307-312 references/evaluation-metrics.md:36-43 references/evaluation-metrics.md:43-60 references/evaluation-metrics.md:60-69 references/evaluation-metrics.md:69-86 references/evaluation-metrics.md:86-97 references/evaluation-metrics.md:97-116 references/evaluation-metrics.md:116-136 references/evaluation-metrics.md:136-146 references/evaluation-metrics.md:146-157 references/evaluation-metrics.md:157-185 references/evaluation-metrics.md:185-196 references/evaluation-metrics.md:196-200 references/evaluation-metrics.md:200-209 references/evaluation-metrics.md:209-221 references/evaluation-metrics.md:221-237 references/evaluation-metrics.md:237-243 references/evaluation-metrics.md:243-253 references/evaluation-metrics.md:253-257 references/evaluation-metrics.md:257-269 references/evaluation-metrics.md:269-273 references/evaluation-metrics.md:273-300 references/evaluation-metrics.md:300-306 references/evaluation-metrics.md:306-352 references/svm-models.md:37 references/svm-models.md:39 references/svm-models.md:40 references/svm-models.md:41 references/svm-models.md:43-52 references/svm-models.md:52-64 references/svm-models.md:64-65 references/svm-models.md:65-66 references/svm-models.md:66-67 references/svm-models.md:67-71 references/svm-models.md:71-72 references/svm-models.md:72-73 references/svm-models.md:73-74 references/svm-models.md:74-75 references/svm-models.md:75-76 references/svm-models.md:76-77 references/svm-models.md:77-79 references/svm-models.md:79-94 references/svm-models.md:94-106 references/svm-models.md:106-107 references/svm-models.md:107-109 references/svm-models.md:109-118 references/svm-models.md:118-133 references/svm-models.md:133-142 references/svm-models.md:142-153 references/svm-models.md:153-162 references/svm-models.md:162-168 references/svm-models.md:168-189 references/svm-models.md:189-193 references/svm-models.md:193-214 references/svm-models.md:214-228 references/svm-models.md:228-231 references/svm-models.md:231-251 references/svm-models.md:251-257 references/svm-models.md:257-279 references/svm-models.md:279-283 references/svm-models.md:283-317 references/svm-models.md:317-321 references/svm-models.md:321-363 references/svm-models.md:363-371 references/svm-models.md:371-377 SKILL.md:39 SKILL.md:40 SKILL.md:41 SKILL.md:43 SKILL.md:47 SKILL.md:48 SKILL.md:49 SKILL.md:50 SKILL.md:52 SKILL.md:56 SKILL.md:57 SKILL.md:58 SKILL.md:59 SKILL.md:61 SKILL.md:65-83 SKILL.md:83-90 SKILL.md:90-98 SKILL.md:98-107 SKILL.md:107-118 SKILL.md:118-126 SKILL.md:126-131 SKILL.md:131-136 SKILL.md:136-141 SKILL.md:141-145 SKILL.md:145-147 SKILL.md:147-153 SKILL.md:153-158 SKILL.md:158-165 SKILL.md:165-172 SKILL.md:172-176 SKILL.md:176-179 SKILL.md:179-183 SKILL.md:183-189 SKILL.md:189-215 SKILL.md:215-219 SKILL.md:219-236 SKILL.md:236-240 SKILL.md:240-261 SKILL.md:261-265 SKILL.md:265-291 SKILL.md:291-297 SKILL.md:297-316 SKILL.md:316-346 SKILL.md:346-347 SKILL.md:347-348 SKILL.md:348-349 SKILL.md:349-350 SKILL.md:350-351 SKILL.md:351-359 SKILL.md:359-364 SKILL.md:364-396
🌐 Network access (3)
Audited by: claude

Jan 4, 2026, 05:01 PM

The skill contains documentation and examples only. No data access, network calls, or execution logic were found.

8
Files scanned
3,979
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude