監査履歴
mulerouter - 6 監査
バージョン比較
監査済みバージョン間の機能と検出結果の変化(新しい順)。
2026年7月5日 20:43
Static analysis raised many findings because this skill combines local Python execution, outbound API calls, and API credential configuration. Manual review found no prompt injection, hidden exfiltration, or arbitrary command execution; most static hits are documentation, tests, placeholders, or expected API client behavior. The remaining contextual concern is that API keys can be supplied on the command line, which may expose secrets through shell history or process inspection.
確認済みのセキュリティ上の懸念 (1)
リスク要因
⚡ スクリプトを含む (8)
🌐 ネットワークアクセス (26)
🔑 環境変数 (58)
⚙️ 外部コマンド (24)
📁 ファイルシステムへのアクセス (1)
2026年7月5日 20:43
Static analysis raised many findings because this skill combines local Python execution, outbound API calls, and API credential configuration. Manual review found no prompt injection, hidden exfiltration, or arbitrary command execution; most static hits are documentation, tests, placeholders, or expected API client behavior. The remaining contextual concern is that API keys can be supplied on the command line, which may expose secrets through shell history or process inspection.
確認済みのセキュリティ上の懸念 (1)
リスク要因
⚡ スクリプトを含む (8)
🌐 ネットワークアクセス (26)
🔑 環境変数 (58)
⚙️ 外部コマンド (24)
📁 ファイルシステムへのアクセス (1)
2026年6月30日 11:36
Static analysis reported a critical heuristic because this skill combines local Python execution, outbound network calls, and API credential access. Manual review found no evidence of malicious exfiltration or prompt injection; the confirmed risk is expected third-party API use with bearer credentials and user-supplied media prompts. Publish with clear warnings about external API transmission and local credential handling.
確認済みのセキュリティ上の懸念 (3)
静的解析の誤検知を無視 (3)
これらの静的マッチはセマンティックレビューで却下されたか、スキーマのみのトークンに一致したため、透明性のために表示されていますが、品質スコアには影響しません。
リスク要因
⚡ スクリプトを含む (8)
🌐 ネットワークアクセス (27)
🔑 環境変数 (64)
⚙️ 外部コマンド (81)
📁 ファイルシステムへのアクセス (1)
検出されたパターン
2026年1月17日 08:07
All 459 static findings are false positives. This is a legitimate AI media generation API client that uses standard patterns for configuration management (environment variables, .env files), API authentication (Bearer tokens to api.mulerouter.ai, api.mulerun.com), and plugin architecture. No credential exfiltration or malicious behavior detected.
リスク要因
🌐 ネットワークアクセス (1)
🔑 環境変数 (1)
⚡ スクリプトを含む (1)
⚙️ 外部コマンド (1)
2026年1月17日 08:07
All 459 static findings are false positives. This is a legitimate AI media generation API client that uses standard patterns for configuration management (environment variables, .env files), API authentication (Bearer tokens to api.mulerouter.ai, api.mulerun.com), and plugin architecture. No credential exfiltration or malicious behavior detected.
リスク要因
🌐 ネットワークアクセス (1)
🔑 環境変数 (1)
⚡ スクリプトを含む (1)
⚙️ 外部コマンド (1)
2026年1月12日 12:11
The static analysis findings are 100% false positives. This is a legitimate AI media generation API client that uses standard patterns for configuration management, API authentication, and plugin architecture. No malicious behavior detected.