Dieser Bericht ist nicht in der angeforderten Sprache verfügbar. Stattdessen wird der maßgebliche englische Bericht angezeigt.

Versionierte Sicherheitsbewertung

Berichts-ID: SA-EF2F7BC8

6/30/2026, 8:13:10 PM

ask-graphql-mcp Sicherheitsbewertung v2

Zertifizierungsbericht zur Skill-Sicherheit

Audit-Verlauf
Auditmodell: codex Historischer Bericht
Skillname
ask-graphql-mcp
Version
v2
Betreuer
SN-Hermes
Abdeckung
4 Gescannte Dateien · 299 Analysierte Zeilen
Richtlinienversion
Nicht verfügbar

Zusammenfassung bestätigter Befunde

Keine bestätigten Sicherheitsbefunde

Das abgeschlossene Audit hat keine bestätigten Sicherheitsbefunde ergeben. Dies ist kein Beweis dafür, dass der Skill keine Nebenwirkungen hat.

Installationskontext

Historische Nachweise

Dieser Bericht beschreibt möglicherweise nicht das derzeit installierbare Artefakt. Öffnen Sie die aktuelle Skill-Seite für Installationshinweise.

Aktuelle Skill-Seite öffnen

Dieser Bericht blockiert oder autorisiert weder das Manifest noch die ZIP-Datei.

Static code-execution and weak-crypto findings are false positives caused by Markdown backticks, JSON examples, and GraphQL text. The network and credential findings are true positives because the skill routes user endpoints, optional endpoint authorization, and paid API keys through a third-party MCP gateway.

Position melden

Historischer Bericht

Öffnen Sie den Auditverlauf, bevor Sie diesen Bericht zur Installation verwenden.

Audit-Nachweis

Nicht bescheinigungsfähig

Die erforderliche unveränderliche Bindung ist unvollständig.

Menschliche Überprüfung

Nicht überprüft

Für diesen Bericht ist keine menschliche Überprüfung verzeichnet.

Abdeckung

4 Gescannte Dateien · 299 Analysierte Zeilen

3 Elemente zur Überprüfung angezeigt

Einschränkungen

Dieser Bericht beansprucht keine Laufzeit- oder Sandbox-Ausführung und beweist nicht das Fehlen von Nebenwirkungen.

Beweiskette

Folgen Sie den Nachweisen von der Quellenbindung bis zum Installationsvertrag. Verfügbare Nachweise unterstützen die Überprüfung; sie sind keine Sicherheitsgarantie.

  1. Quelle

    Bindung nicht verfügbar

  2. Artefakt

    Identität unvollständig

  3. Prüfung

    Vollständig

  4. Installationsvertrag

    Manifest zur Überprüfung öffnen

    Manifest öffnen

Beobachtete Funktionen

„Beobachtet“ bedeutet, dass dieser Bericht unterstützende Nachweise erfasst hat. Nicht erfasst bedeutet nicht, dass eine Fähigkeit nicht vorhanden ist.

Enthält Skripte

Kann mit dem Skill enthaltenen Code ausführen.

Durch dieses Audit nicht erfasst

Netzwerkzugriff

Kann eine Verbindung zu externen Diensten herstellen.

An 6 Nachweisstellen beobachtet

Dateisystemzugriff

Kann lokale Dateien lesen oder schreiben.

Durch dieses Audit nicht erfasst

Umgebungsvariablen

Kann Werte aus der Prozessumgebung lesen.

An 5 Nachweisstellen beobachtet

Externe Befehle

Kann Befehle oder Programme außerhalb des Skills aufrufen.

An 4 Nachweisstellen beobachtet

Elemente der Fähigkeitsprüfung (3)
Hoch
Credential Collection And Third-Party Forwarding
TRUE_POSITIVE. The skill tells agents to request paid API keys and to include X-API-KEY and optional X-ENDPOINT-AUTHORIZATION headers when calling the Hermes MCP gateway. This can expose user credentials or private endpoint tokens to a third-party service. Confidence: 0.88. Confidence reasoning: Multiple files explicitly require credential headers and the SKILL.md text asks users to send an API key in chat, so the credential-handling risk is clear. It is not confirmed malicious because the behavior is documented as part of the service workflow.
Multiple files explicitly require credential headers and the SKILL.md text asks users to send an API key in chat. The behavior is documented, so malicious intent is not proven.
Hoch
Forced Routing Through External MCP Gateway
TRUE_POSITIVE. The skill requires Ask GraphQL MCP as the default path and discourages direct GraphQL calls, even when the model could answer locally or query an endpoint directly. This means user questions and endpoint metadata are intentionally sent to the Hermes gateway. Confidence: 0.82. Confidence reasoning: The routing policy is repeated in SKILL.md and agents/openai.yaml, and the gateway URL is hardcoded. The risk is high for privacy-sensitive endpoints, although the workflow is transparent.
The files repeatedly require use of the external MCP gateway and provide a hardcoded remote URL. The concern is privacy exposure, not covert execution.
Mittel
User-Controlled Endpoint Proxying
TRUE_POSITIVE. The skill instructs agents to pass a user-provided GraphQL endpoint in the X-ENDPOINT header to the MCP gateway. A remote service will likely connect to that endpoint, which creates validation and abuse concerns for private or attacker-controlled URLs. Confidence: 0.74. Confidence reasoning: The endpoint forwarding behavior is explicit, but the actual network request is performed by the external gateway rather than local skill code.
The instructions clearly forward arbitrary user endpoint URLs to the MCP gateway. Impact depends on gateway-side validation that is not visible in this skill.

Risikofunde

Bestätigte Sicherheitsbedenken werden von Punkten getrennt, die noch überprüft werden müssen.

Für dieses abgeschlossene Audit wurden keine bestätigten Sicherheitsbefunde erfasst.

Expertennachweise

Unveränderliche Subjektidentität, Scanner-Metadaten, verworfene Treffer und Nachweise auf Quellcodeebene.

Artefakt-Subjekt

Marketplace-Commit
Nicht verfügbar
Inhalts-Hash
Nicht verfügbar
Tree-Hash
Nicht verfügbar
Skill-Pfad
Nicht verfügbar
Hash der Audit-Nutzlast
Nicht verfügbar

Analysemetadaten

Auditmodell: codex

Analysestatus: Vollständig

Der Umfang ist auf die aufgezeichneten Dateien, Zeilen, Methoden und Nachweise beschränkt. Es wird keine Ausführung in einer Laufzeitumgebung oder Sandbox beansprucht.

Statische falsch positive Treffer ignoriert (3)
Niedrig
Markdown Backticks Flagged As External Commands
FALSE_POSITIVE. Static analysis reported many Ruby or shell backtick executions, but the reviewed files are Markdown and YAML instructions with inline code labels and JSON configuration examples. No executable script, command runner, or shell invocation was found. Confidence: 0.96. Confidence reasoning: The cited lines contain documentation syntax such as tool names, headers, or JSON blocks, not executable code.
The cited lines are documentation and JSON examples. No shell execution primitive appears in the scanned files.
Niedrig
Weak Cryptography Alerts Are Text Matches
FALSE_POSITIVE. Static analysis flagged weak cryptographic algorithm patterns, but the cited locations describe GraphQL or endpoint behavior and do not call cryptographic APIs. No evidence found of MD5, SHA1, DES, or similar weak crypto usage. Confidence: 0.93. Confidence reasoning: The files are declarative instructions and documentation, and the cited lines do not implement cryptography.
The cited text is descriptive and contains no cryptographic implementation. The scanner likely matched substrings in GraphQL-related prose.
Niedrig
Troubleshooting Text Flagged As System Reconnaissance
FALSE_POSITIVE. The cited checks ask the agent to validate gateway URLs, endpoint reachability, headers, and configuration shape. They do not instruct the agent to inspect host files, environment variables, processes, or system information. Confidence: 0.90. Confidence reasoning: The surrounding context is connection troubleshooting for a declared MCP service, not host reconnaissance.
The cited lines are service troubleshooting instructions. No host enumeration commands or sensitive local inspection steps are present.

Verifizieren und exportieren

Das Manifest und die Lockdatei binden Installationsartefakte an kryptografische Hashes. Diese Integritätsaussage ist von der Sicherheitsbewertung getrennt.

Audit-Nachweis: not_attestable