Audit-Verlauf
mulerouter - 6 Audits
Versionsvergleich
Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.
| Version | Datum | Ergebnis | Prüfelemente | Änderung ggü. vorheriger |
|---|---|---|---|---|
| v6 Neueste | 5. Juli 2026, 20:43 | 1 bestätigt | 0 | Keine Änderung der Fähigkeiten |
| v5 | 5. Juli 2026, 20:43 | 1 bestätigt | 0 | Keine Änderung der Fähigkeiten |
| v4 | 30. Juni 2026, 11:36 | 3 bestätigt | 0 | Dateisystemzugriff |
| v3 | 17. Jan. 2026, 08:07 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v2 | 17. Jan. 2026, 08:07 | Keine bestätigten Befunde | 0 | Keine Änderung der Fähigkeiten |
| v1 | 12. Jan. 2026, 12:11 | Keine bestätigten Befunde | 0 | Ausgangsbasis |
5. Juli 2026, 20:43
Static analysis raised many findings because this skill combines local Python execution, outbound API calls, and API credential configuration. Manual review found no prompt injection, hidden exfiltration, or arbitrary command execution; most static hits are documentation, tests, placeholders, or expected API client behavior. The remaining contextual concern is that API keys can be supplied on the command line, which may expose secrets through shell history or process inspection.
Bestätigte Sicherheitsbedenken (1)
Risikofaktoren
⚡ Enthält Skripte (8)
🌐 Netzwerkzugriff (26)
🔑 Umgebungsvariablen (58)
⚙️ Externe Befehle (24)
📁 Dateisystemzugriff (1)
5. Juli 2026, 20:43
Static analysis raised many findings because this skill combines local Python execution, outbound API calls, and API credential configuration. Manual review found no prompt injection, hidden exfiltration, or arbitrary command execution; most static hits are documentation, tests, placeholders, or expected API client behavior. The remaining contextual concern is that API keys can be supplied on the command line, which may expose secrets through shell history or process inspection.
Bestätigte Sicherheitsbedenken (1)
Risikofaktoren
⚡ Enthält Skripte (8)
🌐 Netzwerkzugriff (26)
🔑 Umgebungsvariablen (58)
⚙️ Externe Befehle (24)
📁 Dateisystemzugriff (1)
30. Juni 2026, 11:36
Static analysis reported a critical heuristic because this skill combines local Python execution, outbound network calls, and API credential access. Manual review found no evidence of malicious exfiltration or prompt injection; the confirmed risk is expected third-party API use with bearer credentials and user-supplied media prompts. Publish with clear warnings about external API transmission and local credential handling.
Bestätigte Sicherheitsbedenken (3)
Statische falsch positive Treffer ignoriert (3)
Diese statischen Treffer wurden durch semantische Prüfung verworfen oder entsprachen reinen Schema-Tokens; daher werden sie aus Transparenzgründen angezeigt, beeinflussen jedoch nicht die Qualitätsbewertung.
Risikofaktoren
⚡ Enthält Skripte (8)
🌐 Netzwerkzugriff (27)
🔑 Umgebungsvariablen (64)
⚙️ Externe Befehle (81)
📁 Dateisystemzugriff (1)
Erkannte Muster
17. Jan. 2026, 08:07
All 459 static findings are false positives. This is a legitimate AI media generation API client that uses standard patterns for configuration management (environment variables, .env files), API authentication (Bearer tokens to api.mulerouter.ai, api.mulerun.com), and plugin architecture. No credential exfiltration or malicious behavior detected.
Risikofaktoren
🌐 Netzwerkzugriff (1)
🔑 Umgebungsvariablen (1)
⚡ Enthält Skripte (1)
⚙️ Externe Befehle (1)
17. Jan. 2026, 08:07
All 459 static findings are false positives. This is a legitimate AI media generation API client that uses standard patterns for configuration management (environment variables, .env files), API authentication (Bearer tokens to api.mulerouter.ai, api.mulerun.com), and plugin architecture. No credential exfiltration or malicious behavior detected.
Risikofaktoren
🌐 Netzwerkzugriff (1)
🔑 Umgebungsvariablen (1)
⚡ Enthält Skripte (1)
⚙️ Externe Befehle (1)
12. Jan. 2026, 12:11
The static analysis findings are 100% false positives. This is a legitimate AI media generation API client that uses standard patterns for configuration management, API authentication, and plugin architecture. No malicious behavior detected.