هذا التقرير غير مترجم إلى اللغة المطلوبة. يتم عرض التقرير الإنجليزي الأساسي بدلاً منه.

تقييم أمني مُحدَّث بالإصدار

معرّف التقرير: SA-D5062C00

7/7/2026, 5:43:09 AM

sleek-design-mobile-apps تقييم أمني v3

تقرير شهادة أمان المهارة

سجل التدقيق
نموذج التدقيق: codex تقرير تاريخي
اسم المهارة
sleek-design-mobile-apps
الإصدار
v3
المشرف
sleekdotdesign
التغطية
1 الملفات التي تم فحصها · 435 الأسطر التي تم تحليلها
إصدار السياسة
غير متاح

أعلى مستوى خطورة لنتيجة مؤكدة

متوسط

تتطلب 2 اكتشافات أمنية مؤكدة اهتمامًا.

سياق التثبيت

الأدلة التاريخية

قد لا يصف هذا التقرير العنصر القابل للتثبيت حاليًا. افتح صفحة المهارة الحالية للحصول على إرشادات التثبيت.

افتح صفحة Skill الحالية

لا يحظر هذا التقرير البيان أو ملف ZIP ولا يصرح بهما.

Most external command findings are false positives caused by Markdown backticks and API examples, not executable code. Real risks remain because the skill requires SLEEK_API_KEY, makes bearer-authenticated requests to https://sleek.design, sends user prompts or image URLs to Sleek, and documents project deletion. No evidence of prompt injection, hidden command execution, or unauthorized third-party hosts was found.

موضع التقرير

تقرير تاريخي

افتح سجل التدقيق قبل استخدام هذا التقرير للتثبيت.

إقرار التدقيق

غير قابل للتصديق

الربط الثابت المطلوب غير مكتمل.

التحقق البشري

لم يتم التحقق منه

لم يتم تسجيل أي تحقق بشري لهذا التقرير.

التغطية

1 الملفات التي تم فحصها · 435 الأسطر التي تم تحليلها

19 عناصر معروضة للمراجعة

القيود

لا يدّعي هذا التقرير تنفيذًا في وقت التشغيل أو ضمن بيئة معزولة، ولا يثبت عدم وجود آثار جانبية.

سلسلة الأدلة

اتبع الأدلة من ربط المصدر إلى عقد التثبيت. تدعم الأدلة المتاحة التحقق؛ لكنها ليست ضمانًا للسلامة.

  1. المصدر

    الربط غير متاح

  2. العنصر البرمجي

    الهوية غير مكتملة

  3. التدقيق

    مكتمل

  4. عقد التثبيت

    افتح البيان للتحقق

    افتح البيان

القدرات المرصودة

تعني «تمت ملاحظته» أن هذا التقرير سجل أدلة داعمة. ولا يثبت عدم التسجيل أن القدرة غير موجودة.

يحتوي على سكربتات

قد ينفذ تعليمات برمجية مضمنة مع المهارة.

لم يتم تسجيله بواسطة هذا التدقيق

الوصول إلى الشبكة

قد يتصل بخدمات خارجية.

تمت ملاحظته في 6 مواضع أدلة

الوصول إلى نظام الملفات

قد يقرأ أو يكتب ملفات محلية.

لم يتم تسجيله بواسطة هذا التدقيق

متغيرات البيئة

قد يقرأ قيماً من بيئة العملية.

تمت ملاحظته في 11 مواضع أدلة

الأوامر الخارجية

قد يستدعي أوامر أو برامج خارج المهارة.

تمت ملاحظته في 118 مواضع أدلة

عناصر مراجعة القدرات (17)
مرتفع
Generic API/secret keys
compatibility: Requires SLEEK_API_KEY environment variable. Network access limited to https://sleek.
The skill requires SLEEK_API_KEY and instructs agents to use it as a bearer token for Sleek API calls. This is expected, but misuse of the token could access, modify, screenshot, or delete Sleek projects.
مرتفع
Generic API/secret keys
requires-env: SLEEK_API_KEY
The skill requires SLEEK_API_KEY and instructs agents to use it as a bearer token for Sleek API calls. This is expected, but misuse of the token could access, modify, screenshot, or delete Sleek projects.
مرتفع
Generic API/secret keys
**Auth**: `Authorization: Bearer $SLEEK_API_KEY` on every `/api/v1/*` request
The skill requires SLEEK_API_KEY and instructs agents to use it as a bearer token for Sleek API calls. This is expected, but misuse of the token could access, modify, screenshot, or delete Sleek projects.
مرتفع
Generic API/secret keys
Create API keys at **https://sleek.design/dashboard/api-keys**. The full key value is shown only onc
The skill requires SLEEK_API_KEY and instructs agents to use it as a bearer token for Sleek API calls. This is expected, but misuse of the token could access, modify, screenshot, or delete Sleek projects.
مرتفع
Generic API/secret keys
Authorization: Bearer $SLEEK_API_KEY
The skill requires SLEEK_API_KEY and instructs agents to use it as a bearer token for Sleek API calls. This is expected, but misuse of the token could access, modify, screenshot, or delete Sleek projects.
مرتفع
Generic API/secret keys
Authorization: Bearer $SLEEK_API_KEY
The skill requires SLEEK_API_KEY and instructs agents to use it as a bearer token for Sleek API calls. This is expected, but misuse of the token could access, modify, screenshot, or delete Sleek projects.
مرتفع
Generic API/secret keys
Authorization: Bearer $SLEEK_API_KEY
The skill requires SLEEK_API_KEY and instructs agents to use it as a bearer token for Sleek API calls. This is expected, but misuse of the token could access, modify, screenshot, or delete Sleek projects.
مرتفع
Generic API/secret keys
Authorization: Bearer $SLEEK_API_KEY
The skill requires SLEEK_API_KEY and instructs agents to use it as a bearer token for Sleek API calls. This is expected, but misuse of the token could access, modify, screenshot, or delete Sleek projects.
مرتفع
Generic API/secret keys
Authorization: Bearer $SLEEK_API_KEY
The skill requires SLEEK_API_KEY and instructs agents to use it as a bearer token for Sleek API calls. This is expected, but misuse of the token could access, modify, screenshot, or delete Sleek projects.
مرتفع
Generic API/secret keys
Authorization: Bearer $SLEEK_API_KEY
The skill requires SLEEK_API_KEY and instructs agents to use it as a bearer token for Sleek API calls. This is expected, but misuse of the token could access, modify, screenshot, or delete Sleek projects.
مرتفع
Generic API/secret keys
| Sending to `/api/v1` without `Authorization` header | Add `Authorization: Bearer $SLEEK_API_KEY` t
The skill requires SLEEK_API_KEY and instructs agents to use it as a bearer token for Sleek API calls. This is expected, but misuse of the token could access, modify, screenshot, or delete Sleek projects.
منخفض
Hardcoded URL
compatibility: Requires SLEEK_API_KEY environment variable. Network access limited to https://sleek.
The skill explicitly requires outbound HTTPS requests to https://sleek.design. This is intended and single-host, but user content leaves the local environment.
منخفض
Hardcoded URL
allowed-hosts: https://sleek.design
The skill explicitly requires outbound HTTPS requests to https://sleek.design. This is intended and single-host, but user content leaves the local environment.
منخفض
Hardcoded URL
**Base URL**: `https://sleek.design`
The skill explicitly requires outbound HTTPS requests to https://sleek.design. This is intended and single-host, but user content leaves the local environment.
منخفض
Hardcoded URL
Create API keys at **https://sleek.design/dashboard/api-keys**. The full key value is shown only onc
The line directs users to the external Sleek dashboard for API key setup. This is legitimate onboarding, but it confirms the skill depends on an external service.
منخفض
Hardcoded URL
- **Single host**: All requests go exclusively to `https://sleek.design`. No data is sent to third p
The skill explicitly requires outbound HTTPS requests to https://sleek.design. This is intended and single-host, but user content leaves the local environment.
منخفض
Hardcoded URL
"imageUrls": ["https://example.com/ref.png"],
The example shows imageUrls being sent as visual context, and the skill states Sleek servers may fetch those URLs. This is documented behavior but carries data-sharing risk.

نتائج المخاطر

يتم فصل المخاوف الأمنية المؤكدة عن العناصر التي لا تزال بحاجة إلى مراجعة.

مخاوف أمنية مؤكدة (2)

RISK-001 متوسط
User Content Sent to External AI Service
The skill instructs agents to send the user design request directly as message.text and allows image URLs that Sleek servers may fetch. Sensitive prompts or private images could leave the user environment.
The documentation explicitly says to use the user words directly in message.text and warns that image URLs are fetched by Sleek servers. This strongly supports a third-party data-transfer risk, although it is documented and intentional.
RISK-002 متوسط
Destructive Project Deletion Capability
The skill documents DELETE /api/v1/projects/:id and the projects:write scope. A broad Sleek API key could allow project deletion if the user request is misunderstood or lacks confirmation.
The endpoint table and example section explicitly include project deletion, and the documented projects:write scope enables create and delete operations. The risk depends on token scope and user confirmation practices.

إجراءات المعالجة

سجّل هذا التدقيق الإصلاحات المقترحة. تطبيقها مسؤولية المشرف على الصيانة.

  1. FIX-001
    مرتفع
    API key exposure and broad scopes
    Use the narrowest Sleek API key scopes needed for each task and never log Authorization headers or full key values.
  2. FIX-002
    متوسط
    External transfer of prompts and image URLs
    Ask before sending sensitive prompts or private image URLs to Sleek, and redact confidential information before submission.
  3. FIX-003
    متوسط
    Destructive project deletion
    Require explicit confirmation with the project name and project id before calling DELETE /api/v1/projects/:id.
  4. FIX-004
    منخفض
    Scanner noise from Markdown backticks
    Keep API examples clearly fenced and state that the skill does not include executable scripts or shell commands.

أدلة الخبراء

هوية موضوع غير قابلة للتغيير، وبيانات تعريف الماسح الضوئي، والمطابقات المستبعدة، والأدلة على مستوى المصدر.

موضوع العنصر البرمجي

التزام Marketplace
غير متاح
تجزئة المحتوى
غير متاح
تجزئة الشجرة
غير متاح
مسار Skill
غير متاح
تجزئة حمولة التدقيق
غير متاح

البيانات الوصفية للتحليل

نموذج التدقيق: codex

حالة التحليل: مكتمل

النطاق محدود بالملفات والأسطر والأساليب والأدلة المسجلة. لا يُدّعى تنفيذ وقت التشغيل أو بيئة الاختبار المعزولة.

التحقق والتصدير

يربط البيان وملف القفل عناصر التثبيت بتجزئات تشفيرية. هذا الادعاء المتعلق بالسلامة منفصل عن التقييم الأمني.

إقرار التدقيق: not_attestable