Historique des audits
synthese-multi-llm - 6 audits
Version de l’audit 6
Dernier Risque moyenJun 28, 2026, 08:17 AM
Static analysis found many command, credential, network, filesystem, and hash patterns. Review confirms these are mostly intended multi-LLM orchestration features, not confirmed malicious behavior. The skill should publish with a medium-risk warning because it can send source text to model providers and persist audit data locally.
Problèmes à risque moyen (4)
Problèmes à risque faible (3)
Facteurs de risque
⚙️ Commandes externes (4)
🔑 Variables d’environnement (4)
🌐 Accès réseau (4)
📁 Accès au système de fichiers (3)
⚡ Contient des scripts (3)
Motifs détectés
Version de l’audit 5
Risque faibleJan 16, 2026, 03:20 PM
This is a legitimate multi-LLM orchestration tool for text summarization. The static analyzer's 588 findings are overwhelmingly false positives. The 'weak cryptographic algorithm' findings are markdown documentation being misidentified. 'Shell backtick execution' findings are markdown code formatting. 'API/secret keys' findings are proper environment variable access patterns. The critical heuristics are triggered by legitimate subprocess execution for CLI model calls and API interactions with proper credential handling. No evidence of malicious intent, data exfiltration, or harmful patterns found.
Facteurs de risque
⚙️ Commandes externes (2)
🌐 Accès réseau (1)
📁 Accès au système de fichiers (1)
🔑 Variables d’environnement (1)
Version de l’audit 4
Risque faibleJan 16, 2026, 03:20 PM
This is a legitimate multi-LLM orchestration tool for text summarization. The static analyzer's 588 findings are overwhelmingly false positives. The 'weak cryptographic algorithm' findings are markdown documentation being misidentified. 'Shell backtick execution' findings are markdown code formatting. 'API/secret keys' findings are proper environment variable access patterns. The critical heuristics are triggered by legitimate subprocess execution for CLI model calls and API interactions with proper credential handling. No evidence of malicious intent, data exfiltration, or harmful patterns found.
Facteurs de risque
⚙️ Commandes externes (2)
🌐 Accès réseau (1)
📁 Accès au système de fichiers (1)
🔑 Variables d’environnement (1)
Version de l’audit 3
Risque faibleJan 10, 2026, 10:15 AM
Legitimate multi-LLM synthesis tool. Capabilities align with stated purpose. Subprocess and network calls are documented and expected for calling external LLM services. Input sanitization and validation present. No malicious patterns detected.
Problèmes à risque faible (2)
Facteurs de risque
⚡ Contient des scripts (3)
🌐 Accès réseau (3)
📁 Accès au système de fichiers (2)
🔑 Variables d’environnement (2)
⚙️ Commandes externes (2)
Version de l’audit 2
Risque faibleJan 10, 2026, 10:15 AM
Legitimate multi-LLM synthesis tool. Capabilities align with stated purpose. Subprocess and network calls are documented and expected for calling external LLM services. Input sanitization and validation present. No malicious patterns detected.
Problèmes à risque faible (2)
Facteurs de risque
⚡ Contient des scripts (3)
🌐 Accès réseau (3)
📁 Accès au système de fichiers (2)
🔑 Variables d’environnement (2)
⚙️ Commandes externes (2)
Version de l’audit 1
Risque faibleJan 10, 2026, 10:15 AM
Legitimate multi-LLM synthesis tool. Capabilities align with stated purpose. Subprocess and network calls are documented and expected for calling external LLM services. Input sanitization and validation present. No malicious patterns detected.