nvidia/skills omniverse-cad-to-simready
Checked the catalogued skill at omniverse-cad-to-simready.
F; retained sample includes a high finding · SD-007 · what this rule accepts as a false positive →
D set by findings not listed
B; retained sample includes a medium finding · SD-007 · what this rule accepts as a false positive →
30 suppressed by AI triage
The entry merely references a custom OpenAI-compatible endpoint and does not represent an executable outbound network call or broad permission grant.
The entry lists existing local service URLs as configuration, not an executable network call or permission granting outbound traffic.
The line references a JSON schema URL, not an executable outbound network call or permission grant.
Schema reference URL is a benign configuration reference, not an outbound network call
The path appears only in documentation and does not represent executable code that could traverse the file system.
Schema reference URL is a benign configuration reference, not an outbound network call
Schema reference URL is a benign configuration reference, not an outbound network call
Path check explicitly allows only /var/... prefixes, preventing traversal.
Path check explicitly allows only /var/... prefixes, preventing traversal.
Path check explicitly allows only /var/... prefixes, preventing traversal.
Path check explicitly allows only /var/... prefixes, preventing traversal.
Path check explicitly allows only /var/... prefixes, preventing traversal.
Path check explicitly allows only /var/... prefixes, preventing traversal.
Schema reference URL is a benign configuration reference, not an outbound network call
Reference to JSON schema, not an executed outbound network call
The JSON schema reference is a normal configuration and does not execute or grant outbound network calls.
References a public JSON schema, no active network request
Only a static URL reference, not an outbound call or permission grant.
Only a static URL reference, not an outbound call or permission grant.
Only a static URL reference, not an outbound call or permission grant.
The $schema URL is a metadata reference for a JSON schema and does not trigger an outbound network call.
The code merely assigns a URL string to a variable; no outbound network call is made.
The file only declares a schema URL, not performing an outbound network call.
Referencing the JSON‑schema.org URL is a normal configuration for schema validation and does not initiate an outbound network call.
Referencing the JSON‑schema.org URL is a normal configuration for schema validation and does not initiate an outbound network call.
This is only a JSON schema reference, not an executable network call or permission grant.
The code only imports urllib modules; no outbound call is made here, which is standard library usage.
Decoding a base64 PNG payload is typical image handling, not obfuscation.
Reference to the standard JSON Schema URL is a normal configuration, not an active network call.
Referencing the JSON‑schema.org URL is a normal configuration for schema validation and does not initiate an outbound network call.