هذا التقرير غير مترجم إلى اللغة المطلوبة. يتم عرض التقرير الإنجليزي الأساسي بدلاً منه.

تقييم أمني مُحدَّث بالإصدار

معرّف التقرير: SA-8C6C60F9

6/30/2026, 10:33:32 PM

video-enhancement تقييم أمني v5

تقرير شهادة أمان المهارة

سجل التدقيق
نموذج التدقيق: codex تقرير تاريخي
اسم المهارة
video-enhancement
الإصدار
v5
المشرف
verging.ai
التغطية
2 الملفات التي تم فحصها · 215 الأسطر التي تم تحليلها
إصدار السياسة
غير متاح

أعلى مستوى خطورة لنتيجة مؤكدة

متوسط

تتطلب 3 اكتشافات أمنية مؤكدة اهتمامًا.

سياق التثبيت

الأدلة التاريخية

قد لا يصف هذا التقرير العنصر القابل للتثبيت حاليًا. افتح صفحة المهارة الحالية للحصول على إرشادات التثبيت.

افتح صفحة Skill الحالية

لا يحظر هذا التقرير البيان أو ملف ZIP ولا يصرح بهما.

Static analysis flagged a dangerous combination of shell commands, network access, credential use, and filesystem access. The files are documentation for a video enhancement workflow, so I did not confirm malicious intent or prompt injection, but the skill has elevated operational risk because it uploads user media to a third-party service and uses an API key in shell commands.

موضع التقرير

تقرير تاريخي

افتح سجل التدقيق قبل استخدام هذا التقرير للتثبيت.

إقرار التدقيق

غير قابل للتصديق

الربط الثابت المطلوب غير مكتمل.

التحقق البشري

لم يتم التحقق منه

لم يتم تسجيل أي تحقق بشري لهذا التقرير.

التغطية

2 الملفات التي تم فحصها · 215 الأسطر التي تم تحليلها

3 عناصر معروضة للمراجعة

القيود

لا يدّعي هذا التقرير تنفيذًا في وقت التشغيل أو ضمن بيئة معزولة، ولا يثبت عدم وجود آثار جانبية.

سلسلة الأدلة

اتبع الأدلة من ربط المصدر إلى عقد التثبيت. تدعم الأدلة المتاحة التحقق؛ لكنها ليست ضمانًا للسلامة.

  1. المصدر

    الربط غير متاح

  2. العنصر البرمجي

    الهوية غير مكتملة

  3. التدقيق

    مكتمل

  4. عقد التثبيت

    افتح البيان للتحقق

    افتح البيان

القدرات المرصودة

تعني «تمت ملاحظته» أن هذا التقرير سجل أدلة داعمة. ولا يثبت عدم التسجيل أن القدرة غير موجودة.

يحتوي على سكربتات

قد ينفذ تعليمات برمجية مضمنة مع المهارة.

لم يتم تسجيله بواسطة هذا التدقيق

الوصول إلى الشبكة

قد يتصل بخدمات خارجية.

تمت ملاحظته في 8 مواضع أدلة

الوصول إلى نظام الملفات

قد يقرأ أو يكتب ملفات محلية.

تمت ملاحظته في 4 مواضع أدلة

متغيرات البيئة

قد يقرأ قيماً من بيئة العملية.

تمت ملاحظته في 8 مواضع أدلة

الأوامر الخارجية

قد يستدعي أوامر أو برامج خارج المهارة.

تمت ملاحظته في 12 مواضع أدلة

نتائج المخاطر

يتم فصل المخاوف الأمنية المؤكدة عن العناصر التي لا تزال بحاجة إلى مراجعة.

مخاوف أمنية مؤكدة (3)

RISK-001 متوسط
Third-Party Video Upload Workflow
The skill instructs the agent to request an upload URL, upload a local video or trimmed clip, and create a remote enhancement job. This is expected for the service, but it can expose user media to verging.ai and a presigned storage endpoint.
The workflow explicitly uploads video content to remote URLs and creates a third-party processing job. The behavior is documented and service-related, but it is a real data exposure risk for sensitive media.
RISK-002 متوسط
Shell Commands Operate on User-Supplied Paths and URLs
The skill tells the agent to use yt-dlp, ffprobe, ffmpeg, and curl with a user-provided video path or URL. This is legitimate media tooling, but it needs careful argument handling and user consent before processing remote URLs or local files.
The command examples and execution flow clearly use external binaries with user-controlled inputs. No direct command injection payload is present, so the risk depends on implementation and quoting.
RISK-003 متوسط
API Key Used in Command-Line Requests
The skill requires VERGING_API_KEY and places it in curl Authorization headers. This is normal for an API client, but command histories, logs, or shared terminal output can expose the key if not handled carefully.
The documentation directly requires an API key and shows it in Authorization headers. The examples use an environment variable in most places, which reduces but does not remove exposure risk.

أدلة الخبراء

هوية موضوع غير قابلة للتغيير، وبيانات تعريف الماسح الضوئي، والمطابقات المستبعدة، والأدلة على مستوى المصدر.

موضوع العنصر البرمجي

التزام Marketplace
غير متاح
تجزئة المحتوى
غير متاح
تجزئة الشجرة
غير متاح
مسار Skill
غير متاح
تجزئة حمولة التدقيق
غير متاح

البيانات الوصفية للتحليل

نموذج التدقيق: codex

حالة التحليل: مكتمل

النطاق محدود بالملفات والأسطر والأساليب والأدلة المسجلة. لا يُدّعى تنفيذ وقت التشغيل أو بيئة الاختبار المعزولة.

تم تجاهل الإيجابيات الكاذبة الثابتة (2)
منخفض
Hardcoded Service URLs Are Expected
The hardcoded verging.ai and documentation URLs are expected for a vendor-specific video enhancement skill. They are still relevant because they confirm network dependency on a third-party service.
The URLs point to the advertised service and related API endpoints. I did not find evidence of unrelated or covert exfiltration endpoints.
منخفض
Weak Cryptography Alert Not Supported by Context
The static weak-cryptography alerts appear to be triggered by markdown text and table formatting, not by code that implements cryptographic algorithms. No evidence found of MD5, SHA1, or custom cryptography being used.
The cited lines contain prose or markdown table headers. They do not contain cryptographic functions, algorithm names, or executable code.

التحقق والتصدير

يربط البيان وملف القفل عناصر التثبيت بتجزئات تشفيرية. هذا الادعاء المتعلق بالسلامة منفصل عن التقييم الأمني.

إقرار التدقيق: not_attestable