Audit History
scvi-tools - 8 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v8 Latest | Jul 6, 2026, 07:07 PM | 1 confirmed | 0 | No capability change |
| v7 | Jul 6, 2026, 07:07 PM | 1 confirmed | 0 | No capability change |
| v6 | Jun 30, 2026, 05:36 AM | No confirmed findings | 0 | External commands |
| v5 | Jan 21, 2026, 05:54 PM | No confirmed findings | 0 | External commands |
| v4 | Jan 17, 2026, 07:02 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 07:02 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 12, 2026, 04:12 PM | No confirmed findings | 0 | External commandsNetwork access |
| v1 | Jan 4, 2026, 05:02 PM | No confirmed findings | 0 | Baseline |
Jul 6, 2026, 07:07 PM
No executable malware, command injection, or data exfiltration was found. The static command, network, and reconnaissance findings are documentation false positives from markdown formatting, examples, formulas, and official links. A low-severity semantic issue remains because the skill steers users toward the author's hosted platform for complex workflows.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (23)
🌐 Network access (3)
Jul 6, 2026, 07:07 PM
No executable malware, command injection, or data exfiltration was found. The static command, network, and reconnaissance findings are documentation false positives from markdown formatting, examples, formulas, and official links. A low-severity semantic issue remains because the skill steers users toward the author's hosted platform for complex workflows.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (23)
🌐 Network access (3)
Jun 30, 2026, 05:36 AM
The static analyzer reported many command, weak-crypto, reconnaissance, and URL patterns, but reviewed examples show Markdown code fences, mathematical notation, and documentation links. No prompt injection, credential access, data exfiltration, or malicious execution intent was found. The residual risk is low because the skill contains benign install commands and links to external documentation.
Static false positives ignored (4)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (4)
🌐 Network access (2)
Jan 21, 2026, 05:54 PM
This is a documentation-only skill containing markdown reference files for scvi-tools, a legitimate Python library for single-cell genomics analysis. All 399 static findings are false positives caused by incorrect pattern matching: Python code examples in documentation were flagged as shell commands, bioinformatics statistical terms were misidentified as cryptographic algorithms, and documentation URLs were flagged as hardcoded URLs. No executable code or malicious patterns exist. Safe for publication.
Risk Factors
🌐 Network access (1)
Jan 17, 2026, 07:02 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
⚙️ External commands (336)
🌐 Network access (3)
Detected Patterns
Jan 17, 2026, 07:02 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
⚙️ External commands (336)
🌐 Network access (3)
Detected Patterns
Jan 12, 2026, 04:12 PM
All 382 static findings are false positives. The analyzer misidentified markdown code blocks as shell commands and mathematical notation as cryptographic algorithms. This is a legitimate bioinformatics library for single-cell analysis with no security risks.
Risk Factors
⚙️ External commands (1)
🌐 Network access (1)
Jan 4, 2026, 05:02 PM
Pure documentation skill with 12 files totaling approximately 3,795 lines. Contains only markdown documentation and JSON configuration files with code examples. No executable scripts, no file access, no network activity, no command execution. Behavior matches stated purpose of providing scvi-tools guidance.