هذا التقرير غير مترجم إلى اللغة المطلوبة. يتم عرض التقرير الإنجليزي الأساسي بدلاً منه.

تقييم أمني مُحدَّث بالإصدار

معرّف التقرير: SA-5A0E4804

6/30/2026, 7:59:53 PM

sleek-design-mobile-apps تقييم أمني v2

تقرير شهادة أمان المهارة

سجل التدقيق
نموذج التدقيق: codex تقرير تاريخي
اسم المهارة
sleek-design-mobile-apps
الإصدار
v2
المشرف
sleekdotdesign
التغطية
1 الملفات التي تم فحصها · 435 الأسطر التي تم تحليلها
إصدار السياسة
غير متاح

أعلى مستوى خطورة لنتيجة مؤكدة

متوسط

تتطلب 3 اكتشافات أمنية مؤكدة اهتمامًا.

سياق التثبيت

الأدلة التاريخية

قد لا يصف هذا التقرير العنصر القابل للتثبيت حاليًا. افتح صفحة المهارة الحالية للحصول على إرشادات التثبيت.

افتح صفحة Skill الحالية

لا يحظر هذا التقرير البيان أو ملف ZIP ولا يصرح بهما.

Static external command and weak cryptography findings are false positives caused by Markdown backticks, endpoint examples, and inline API terms in SKILL.md. The confirmed risks are intentional network access to https://sleek.design, use of SLEEK_API_KEY, and optional image URL fetching by Sleek servers, so the skill is publishable with a network and credential warning.

موضع التقرير

تقرير تاريخي

افتح سجل التدقيق قبل استخدام هذا التقرير للتثبيت.

إقرار التدقيق

غير قابل للتصديق

الربط الثابت المطلوب غير مكتمل.

التحقق البشري

لم يتم التحقق منه

لم يتم تسجيل أي تحقق بشري لهذا التقرير.

التغطية

1 الملفات التي تم فحصها · 435 الأسطر التي تم تحليلها

3 عناصر معروضة للمراجعة

القيود

لا يدّعي هذا التقرير تنفيذًا في وقت التشغيل أو ضمن بيئة معزولة، ولا يثبت عدم وجود آثار جانبية.

سلسلة الأدلة

اتبع الأدلة من ربط المصدر إلى عقد التثبيت. تدعم الأدلة المتاحة التحقق؛ لكنها ليست ضمانًا للسلامة.

  1. المصدر

    الربط غير متاح

  2. العنصر البرمجي

    الهوية غير مكتملة

  3. التدقيق

    مكتمل

  4. عقد التثبيت

    افتح البيان للتحقق

    افتح البيان

القدرات المرصودة

تعني «تمت ملاحظته» أن هذا التقرير سجل أدلة داعمة. ولا يثبت عدم التسجيل أن القدرة غير موجودة.

يحتوي على سكربتات

قد ينفذ تعليمات برمجية مضمنة مع المهارة.

لم يتم تسجيله بواسطة هذا التدقيق

الوصول إلى الشبكة

قد يتصل بخدمات خارجية.

تمت ملاحظته في 5 مواضع أدلة

الوصول إلى نظام الملفات

قد يقرأ أو يكتب ملفات محلية.

لم يتم تسجيله بواسطة هذا التدقيق

متغيرات البيئة

قد يقرأ قيماً من بيئة العملية.

تمت ملاحظته في 5 مواضع أدلة

الأوامر الخارجية

قد يستدعي أوامر أو برامج خارج المهارة.

لم يتم تسجيله بواسطة هذا التدقيق

نتائج المخاطر

يتم فصل المخاوف الأمنية المؤكدة عن العناصر التي لا تزال بحاجة إلى مراجعة.

مخاوف أمنية مؤكدة (3)

RISK-001 متوسط
Authorized External API Access
The skill instructs agents to send project names, prompts, component IDs, and screenshots requests to https://sleek.design. This is core functionality, but users should know their design content leaves the local environment.
The skill explicitly documents REST API calls to a single external host with user-provided design prompts and optional images. The behavior is intentional and scoped, but it is still real network disclosure.
RISK-002 متوسط
API Key Required For Bearer Authentication
The skill requires SLEEK_API_KEY and uses it in Authorization headers for Sleek API calls. This is legitimate credential use, but key scope and storage should be handled carefully.
The environment variable and Authorization header are directly documented. The key is sent only to Sleek endpoints in the instructions, so this is a controlled but sensitive capability.
RISK-003 منخفض
Image URL Fetching Has Privacy Implications
The skill allows imageUrls in chat messages and states those URLs are fetched by Sleek servers. This is documented, but users should avoid private or sensitive URLs.
The behavior is clearly documented and may be legitimate visual context handling. The risk depends on what URLs users provide, so this is a lower-severity privacy concern.

أدلة الخبراء

هوية موضوع غير قابلة للتغيير، وبيانات تعريف الماسح الضوئي، والمطابقات المستبعدة، والأدلة على مستوى المصدر.

موضوع العنصر البرمجي

التزام Marketplace
غير متاح
تجزئة المحتوى
غير متاح
تجزئة الشجرة
غير متاح
مسار Skill
غير متاح
تجزئة حمولة التدقيق
غير متاح

البيانات الوصفية للتحليل

نموذج التدقيق: codex

حالة التحليل: مكتمل

النطاق محدود بالملفات والأسطر والأساليب والأدلة المسجلة. لا يُدّعى تنفيذ وقت التشغيل أو بيئة الاختبار المعزولة.

تم تجاهل الإيجابيات الكاذبة الثابتة (4)
منخفض
External Command Findings Are Markdown False Positives
The static analyzer flagged many inline backticks and fenced examples as Ruby or shell backtick execution. SKILL.md is documentation and contains HTTP examples, endpoint paths, field names, and Markdown tables, not executable Ruby code.
Line review shows Markdown code formatting and HTTP request examples, not a script interpreter or command execution API. No executable files or shell invocations were present in the scanned file.
منخفض
Weak Cryptography Findings Are Documentation False Positives
The static weak cryptography alerts do not correspond to cryptographic code. The referenced lines contain YAML metadata, API documentation, text examples, or screenshot option names.
Reviewed lines do not define hashing, encryption, random number generation, or cryptographic verification. The alerts appear to be token-level matches inside prose and API examples.
منخفض
System Reconnaissance Findings Are False Positives
The system reconnaissance alerts map to documentation about image URLs, screenshot dot-grid options, and HTTP error codes. No host probing, environment enumeration, or local system discovery instructions were found.
The referenced text is API documentation and rendering configuration. It does not instruct the agent to inspect local systems or enumerate network targets.
منخفض
Critical Combination Heuristic Is Not Confirmed
The static analyzer combined code execution, network, and credential signals into a critical heuristic. Context review found no executable code path; the network and credential use are documented Sleek API operations.
The heuristic depends on a code execution signal, but reviewed evidence is Markdown and HTTP documentation only. Network and API key use remain real but scoped to the described vendor API.

التحقق والتصدير

يربط البيان وملف القفل عناصر التثبيت بتجزئات تشفيرية. هذا الادعاء المتعلق بالسلامة منفصل عن التقييم الأمني.

إقرار التدقيق: not_attestable