سجل التدقيق
agent-tools - 4 عمليات التدقيق
مقارنة الإصدارات
التغييرات في القدرات والنتائج عبر الإصدارات المدقّقة، الأحدث أولاً.
٥ يوليو ٢٠٢٦، ٠٣:١٢ م
The skill is legitimate CLI documentation for inference.sh, but it includes confirmed remote shell installer instructions and many external infsh commands. Most hardcoded documentation links and API-key mentions are false positives, while cloud execution and Twitter/X automation remain meaningful operational risks. No prompt injection text was found in the reviewed files.
مخاوف أمنية مؤكدة (6)
عناصر مراجعة القدرات (16)
هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.
عوامل الخطر
🌐 الوصول إلى الشبكة (14)
🔑 متغيرات البيئة (3)
📁 الوصول إلى نظام الملفات (2)
الأنماط المكتشفة
٥ يوليو ٢٠٢٦، ٠٣:١٢ م
The skill is legitimate CLI documentation for inference.sh, but it includes confirmed remote shell installer instructions and many external infsh commands. Most hardcoded documentation links and API-key mentions are false positives, while cloud execution and Twitter/X automation remain meaningful operational risks. No prompt injection text was found in the reviewed files.
مخاوف أمنية مؤكدة (6)
عناصر مراجعة القدرات (16)
هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.
عوامل الخطر
🌐 الوصول إلى الشبكة (14)
🔑 متغيرات البيئة (3)
📁 الوصول إلى نظام الملفات (2)
الأنماط المكتشفة
٣٠ يونيو ٢٠٢٦، ٠٣:٢٨ ص
Static analysis correctly identified many shell command examples, network references, credential handling notes, and local file writes. Most external command findings are documentation for the intended inference.sh workflow, and no prompt injection or malicious exfiltration intent was found. Publication is reasonable with a warning because the skill asks users to install and run a networked CLI that can submit prompts, files, and tasks to a third-party service.
عناصر مراجعة القدرات (4)
هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.
تم تجاهل الإيجابيات الكاذبة الثابتة (1)
تم تجاهل هذه المطابقات الثابتة بواسطة المراجعة الدلالية أو لأنها طابقت رموزًا خاصة بالمخطط فقط، لذا تُعرض للشفافية لكنها لا تؤثر في درجة الجودة.
عوامل الخطر
⚙️ الأوامر الخارجية (132)
🌐 الوصول إلى الشبكة (28)
🔑 متغيرات البيئة (3)
📁 الوصول إلى نظام الملفات (2)
الأنماط المكتشفة
١٢ فبراير ٢٠٢٦، ٠٨:٥٦ ص
All 182 static analysis findings are false positives. This skill provides documentation for the inference.sh CLI tool - bash code blocks are instructional examples, not executable code. URLs are documentation links. The pipe-to-shell pattern is the standard installation method for CLI tools. No malicious code, prompt injection, or security threats detected.