監査履歴
synthese-multi-llm - 5 監査
監査バージョン 5
最新 低リスクJan 16, 2026, 03:20 PM
This is a legitimate multi-LLM orchestration tool for text summarization. The static analyzer's 588 findings are overwhelmingly false positives. The 'weak cryptographic algorithm' findings are markdown documentation being misidentified. 'Shell backtick execution' findings are markdown code formatting. 'API/secret keys' findings are proper environment variable access patterns. The critical heuristics are triggered by legitimate subprocess execution for CLI model calls and API interactions with proper credential handling. No evidence of malicious intent, data exfiltration, or harmful patterns found.
リスク要因
⚙️ 外部コマンド (2)
🌐 ネットワークアクセス (1)
📁 ファイルシステムへのアクセス (1)
監査バージョン 4
低リスクJan 16, 2026, 03:20 PM
This is a legitimate multi-LLM orchestration tool for text summarization. The static analyzer's 588 findings are overwhelmingly false positives. The 'weak cryptographic algorithm' findings are markdown documentation being misidentified. 'Shell backtick execution' findings are markdown code formatting. 'API/secret keys' findings are proper environment variable access patterns. The critical heuristics are triggered by legitimate subprocess execution for CLI model calls and API interactions with proper credential handling. No evidence of malicious intent, data exfiltration, or harmful patterns found.
リスク要因
⚙️ 外部コマンド (2)
🌐 ネットワークアクセス (1)
📁 ファイルシステムへのアクセス (1)
監査バージョン 3
低リスクJan 10, 2026, 10:15 AM
Legitimate multi-LLM synthesis tool. Capabilities align with stated purpose. Subprocess and network calls are documented and expected for calling external LLM services. Input sanitization and validation present. No malicious patterns detected.
低リスクの問題 (2)
リスク要因
🌐 ネットワークアクセス (3)
📁 ファイルシステムへのアクセス (2)
監査バージョン 2
低リスクJan 10, 2026, 10:15 AM
Legitimate multi-LLM synthesis tool. Capabilities align with stated purpose. Subprocess and network calls are documented and expected for calling external LLM services. Input sanitization and validation present. No malicious patterns detected.
低リスクの問題 (2)
リスク要因
🌐 ネットワークアクセス (3)
📁 ファイルシステムへのアクセス (2)
監査バージョン 1
低リスクJan 10, 2026, 10:15 AM
Legitimate multi-LLM synthesis tool. Capabilities align with stated purpose. Subprocess and network calls are documented and expected for calling external LLM services. Input sanitization and validation present. No malicious patterns detected.