Audit-Verlauf
ai-video-generation - 4 Audits
Versionsvergleich
Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.
| Version | Datum | Ergebnis | Prüfelemente | Änderung ggü. vorheriger |
|---|---|---|---|---|
| v4 Neueste | 5. Juli 2026, 17:44 | 1 bestätigt | 0 | Keine Änderung der Fähigkeiten |
| v3 | 5. Juli 2026, 17:44 | 1 bestätigt | 0 | Keine Änderung der Fähigkeiten |
| v2 | 30. Juni 2026, 04:14 | Keine bestätigten Befunde | 2 | Externe BefehleNetzwerkzugriff |
| v1 | 11. Mai 2026, 09:22 | Keine bestätigten Befunde | 0 | Ausgangsbasis |
5. Juli 2026, 17:44
The static Ruby backtick and hardcoded URL findings are false positives caused by Markdown code spans, fenced command examples, model IDs, and documentation links. No prompt injection or hidden malicious behavior was found in SKILL.md. The remaining concern is expected external processing of prompts and media URLs through the inference.sh belt CLI.
Bestätigte Sicherheitsbedenken (1)
Risikofaktoren
⚙️ Externe Befehle (59)
5. Juli 2026, 17:44
The static Ruby backtick and hardcoded URL findings are false positives caused by Markdown code spans, fenced command examples, model IDs, and documentation links. No prompt injection or hidden malicious behavior was found in SKILL.md. The remaining concern is expected external processing of prompts and media URLs through the inference.sh belt CLI.
Bestätigte Sicherheitsbedenken (1)
Risikofaktoren
⚙️ Externe Befehle (59)
30. Juni 2026, 04:14
The static backtick and weak-crypto findings are mostly false positives caused by Markdown code fences, inline model identifiers, and the word Description. The real risk is that the skill authorizes Bash(belt *) and instructs agents to submit prompts and user media URLs to external inference.sh model services, which is legitimate for the skill but requires user awareness.
Elemente der Fähigkeitsprüfung (2)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.
Statische falsch positive Treffer ignoriert (3)
Diese statischen Treffer wurden durch semantische Prüfung verworfen oder entsprachen reinen Schema-Tokens; daher werden sie aus Transparenzgründen angezeigt, beeinflussen jedoch nicht die Qualitätsbewertung.
Risikofaktoren
⚙️ Externe Befehle (9)
Erkannte Muster
11. Mai 2026, 09:22
The skill is a legitimate AI video generation tool using the inference.sh CLI (belt). Static findings flagged 59 external_command locations and 19 network locations, but evaluation confirms all are FALSE POSITIVES. The backtick syntax in SKILL.md markdown code blocks is documentation only (not executable Ruby), and hardcoded URLs reference legitimate service documentation and user-provided media URLs. No command injection vectors exist. The skill only invokes the belt CLI with hardcoded app IDs and JSON parameters, no user input is interpolated into shell commands.