Historial de auditorías
synthese-multi-llm - 6 auditorías
Versión de auditoría 6
Más reciente Riesgo medioJun 28, 2026, 08:17 AM
Static analysis found many command, credential, network, filesystem, and hash patterns. Review confirms these are mostly intended multi-LLM orchestration features, not confirmed malicious behavior. The skill should publish with a medium-risk warning because it can send source text to model providers and persist audit data locally.
Problemas de riesgo medio (4)
Problemas de riesgo bajo (3)
Factores de riesgo
⚙️ Comandos externos (4)
🔑 Variables de entorno (4)
🌐 Acceso a red (4)
📁 Acceso al sistema de archivos (3)
⚡ Contiene scripts (3)
Patrones detectados
Versión de auditoría 5
Riesgo bajoJan 16, 2026, 03:20 PM
This is a legitimate multi-LLM orchestration tool for text summarization. The static analyzer's 588 findings are overwhelmingly false positives. The 'weak cryptographic algorithm' findings are markdown documentation being misidentified. 'Shell backtick execution' findings are markdown code formatting. 'API/secret keys' findings are proper environment variable access patterns. The critical heuristics are triggered by legitimate subprocess execution for CLI model calls and API interactions with proper credential handling. No evidence of malicious intent, data exfiltration, or harmful patterns found.
Factores de riesgo
⚙️ Comandos externos (2)
🌐 Acceso a red (1)
📁 Acceso al sistema de archivos (1)
🔑 Variables de entorno (1)
Versión de auditoría 4
Riesgo bajoJan 16, 2026, 03:20 PM
This is a legitimate multi-LLM orchestration tool for text summarization. The static analyzer's 588 findings are overwhelmingly false positives. The 'weak cryptographic algorithm' findings are markdown documentation being misidentified. 'Shell backtick execution' findings are markdown code formatting. 'API/secret keys' findings are proper environment variable access patterns. The critical heuristics are triggered by legitimate subprocess execution for CLI model calls and API interactions with proper credential handling. No evidence of malicious intent, data exfiltration, or harmful patterns found.
Factores de riesgo
⚙️ Comandos externos (2)
🌐 Acceso a red (1)
📁 Acceso al sistema de archivos (1)
🔑 Variables de entorno (1)
Versión de auditoría 3
Riesgo bajoJan 10, 2026, 10:15 AM
Legitimate multi-LLM synthesis tool. Capabilities align with stated purpose. Subprocess and network calls are documented and expected for calling external LLM services. Input sanitization and validation present. No malicious patterns detected.
Problemas de riesgo bajo (2)
Factores de riesgo
⚡ Contiene scripts (3)
🌐 Acceso a red (3)
📁 Acceso al sistema de archivos (2)
🔑 Variables de entorno (2)
⚙️ Comandos externos (2)
Versión de auditoría 2
Riesgo bajoJan 10, 2026, 10:15 AM
Legitimate multi-LLM synthesis tool. Capabilities align with stated purpose. Subprocess and network calls are documented and expected for calling external LLM services. Input sanitization and validation present. No malicious patterns detected.
Problemas de riesgo bajo (2)
Factores de riesgo
⚡ Contiene scripts (3)
🌐 Acceso a red (3)
📁 Acceso al sistema de archivos (2)
🔑 Variables de entorno (2)
⚙️ Comandos externos (2)
Versión de auditoría 1
Riesgo bajoJan 10, 2026, 10:15 AM
Legitimate multi-LLM synthesis tool. Capabilities align with stated purpose. Subprocess and network calls are documented and expected for calling external LLM services. Input sanitization and validation present. No malicious patterns detected.