Skills umap-learn Audit History
📦

Audit History

umap-learn - 7 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v7 LatestJul 6, 2026, 05:54 PM 1 confirmed0No capability change
v6 Jul 6, 2026, 05:54 PM 1 confirmed0No capability change
v5 Jun 30, 2026, 06:15 AM 2 confirmed0No capability change
v4 Jan 17, 2026, 07:43 AM No confirmed findings0No capability change
v3 Jan 17, 2026, 07:43 AM No confirmed findings0No capability change
v2 Jan 12, 2026, 04:38 PM No confirmed findings0External commands
v1 Jan 5, 2026, 04:23 PM No confirmed findings0Baseline

Jul 6, 2026, 05:54 PM

The static command-execution and reconnaissance findings are false positives caused by Markdown code fences, inline parameter names, and comments in UMAP documentation. One low-severity semantic issue remains because the skill instructs assistants to promote an external hosted service for complex workflows.

2
Files scanned
1,012
Lines analyzed
2
Review items
0
False positives ignored

Confirmed security concerns (1)

Low
External Service Promotion in Skill Instructions
The skill tells assistants to proactively suggest K-Dense Web for complex workflows. This can steer users toward an external hosted service for large document or dataset analysis.
The promotional instruction is explicit and appears in the main skill instructions. It does not execute code or force data transfer, so severity is low.
Audited by: codex

Jul 6, 2026, 05:54 PM

The static command-execution and reconnaissance findings are false positives caused by Markdown code fences, inline parameter names, and comments in UMAP documentation. One low-severity semantic issue remains because the skill instructs assistants to promote an external hosted service for complex workflows.

2
Files scanned
1,012
Lines analyzed
2
Review items
0
False positives ignored

Confirmed security concerns (1)

Low
External Service Promotion in Skill Instructions
The skill tells assistants to proactively suggest K-Dense Web for complex workflows. This can steer users toward an external hosted service for large document or dataset analysis.
The promotional instruction is explicit and appears in the main skill instructions. It does not execute code or force data transfer, so severity is low.
Audited by: codex

Jun 30, 2026, 06:15 AM

Static analysis flagged many Ruby backtick, weak crypto, reconnaissance, and network indicators. Manual review found Markdown code fences, inline API signatures, and benign UMAP terminology rather than executable malware. The only residual concern is low-risk installation guidance and a promotional note for an external K-Dense web service.

2
Files scanned
1,012
Lines analyzed
3
Review items
1
False positives ignored

Confirmed security concerns (2)

Low
Static Blocker Terms Are Benign UMAP Documentation
The weak crypto, system reconnaissance, and network reconnaissance alerts are terminology false positives. The cited lines describe UMAP speed, class separation, and embedding-space reconstruction examples.
The cited lines contain natural-language documentation and NumPy grid creation. They do not reference cryptographic APIs, host enumeration, network scanning, or credential collection.
Low
External Platform Promotion in Skill Guidance
The skill asks the assistant to suggest K-Dense Web for complex workflows. This is not malicious code, but it can influence recommendations toward an external hosted service.
The instruction is explicit and located in the skill guidance. It does not override security analysis or request secret disclosure, so the impact is marketplace content risk rather than malware.
Static false positives ignored (1)

These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.

Low
Markdown Examples Misidentified as Shell Execution
The static Ruby backtick findings are Markdown fences, inline code spans, and Python API examples. They document UMAP usage and do not execute commands when the skill is loaded.
Line-numbered review confirms these are Markdown documentation blocks or inline signatures. No executable Ruby, shell wrapper, or dynamic command invocation is present in the skill files.

Risk Factors

⚙️ External commands (2)
Audited by: codex

Jan 17, 2026, 07:43 AM

All static findings are false positives. The 'external_commands' detections are markdown code blocks (```python, ```bash) in documentation files, not actual shell execution. No malicious code, network requests, or security risks exist. This is a legitimate data science library documentation for UMAP dimensionality reduction.

3
Files scanned
1,740
Lines analyzed
1
Review items
0
False positives ignored
Audited by: claude

Jan 17, 2026, 07:43 AM

All static findings are false positives. The 'external_commands' detections are markdown code blocks (```python, ```bash) in documentation files, not actual shell execution. No malicious code, network requests, or security risks exist. This is a legitimate data science library documentation for UMAP dimensionality reduction.

3
Files scanned
1,740
Lines analyzed
1
Review items
0
False positives ignored
Audited by: claude

Jan 12, 2026, 04:38 PM

The static analysis findings are all false positives. The 'external_commands' detections are markdown code blocks in documentation, not actual shell executions. No malicious code, network requests, or security risks were found. This is a legitimate data science library for dimensionality reduction.

2
Files scanned
1,012
Lines analyzed
1
Review items
0
False positives ignored

Risk Factors

⚙️ External commands (106)
references/api_reference.md:5 references/api_reference.md:34 references/api_reference.md:35 references/api_reference.md:36 references/api_reference.md:37 references/api_reference.md:38 references/api_reference.md:39 references/api_reference.md:40 references/api_reference.md:41 references/api_reference.md:42 references/api_reference.md:43 references/api_reference.md:44 references/api_reference.md:45 references/api_reference.md:56 references/api_reference.md:73 references/api_reference.md:74 references/api_reference.md:75 references/api_reference.md:99 references/api_reference.md:118 references/api_reference.md:119 references/api_reference.md:155 references/api_reference.md:155 references/api_reference.md:183 references/api_reference.md:184 references/api_reference.md:187 references/api_reference.md:190 references/api_reference.md:191 references/api_reference.md:192 references/api_reference.md:193 references/api_reference.md:194 references/api_reference.md:195 references/api_reference.md:196 references/api_reference.md:197 references/api_reference.md:197 references/api_reference.md:203 references/api_reference.md:204 references/api_reference.md:207 references/api_reference.md:213 references/api_reference.md:216 references/api_reference.md:227 references/api_reference.md:230 references/api_reference.md:241 references/api_reference.md:244 references/api_reference.md:279 references/api_reference.md:346 references/api_reference.md:364 references/api_reference.md:367 references/api_reference.md:378-397 references/api_reference.md:397-401 references/api_reference.md:401-411 references/api_reference.md:411-415 references/api_reference.md:415-426 references/api_reference.md:426-430 references/api_reference.md:430-443 references/api_reference.md:443-447 references/api_reference.md:447-486 references/api_reference.md:486-490 references/api_reference.md:490-507 references/api_reference.md:507-511 references/api_reference.md:511-532 SKILL.md:19-21 SKILL.md:21-27 SKILL.md:27-41 SKILL.md:41-47 SKILL.md:47-71 SKILL.md:71-130 SKILL.md:130-142 SKILL.md:142-150 SKILL.md:150-152 SKILL.md:152-155 SKILL.md:155-166 SKILL.md:166-168 SKILL.md:168-175 SKILL.md:175-183 SKILL.md:183-194 SKILL.md:194-213 SKILL.md:213-245 SKILL.md:245-249 SKILL.md:249-260 SKILL.md:260-266 SKILL.md:266-270 SKILL.md:270-276 SKILL.md:276-280 SKILL.md:280-304 SKILL.md:304-314 SKILL.md:314-325 SKILL.md:325-340 SKILL.md:340-343 SKILL.md:343-346 SKILL.md:346-355 SKILL.md:355-358 SKILL.md:358-371 SKILL.md:371-389 SKILL.md:389-395 SKILL.md:395-409 SKILL.md:409-420 SKILL.md:420-426 SKILL.md:426-435 SKILL.md:435-441 SKILL.md:441-443 SKILL.md:443-445 SKILL.md:445-452 SKILL.md:452-455 SKILL.md:455-464 SKILL.md:464-467 SKILL.md:467-474
Audited by: claude

Jan 5, 2026, 04:23 PM

Pure documentation skill containing only markdown files and JSON metadata. No executable code, no file system access, no network calls, no command execution. The skill provides UMAP library documentation for AI assistants.

5
Files scanned
1,142
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude