監査履歴
ai-avatar-video - 5 監査
バージョン比較
監査済みバージョン間の機能と検出結果の変化(新しい順)。
2026年9月7日 15:57
The skill legitimately invokes hosted inference models, so command blocks that run belt, redirect outputs, loop over jobs, or install packages are confirmed. Formatting-only backticks and placeholder or documentation URLs are false positives, while the remote image carries a minor privacy risk. The UGC workflow also encourages synthetic testimonials designed to appear authentic.
確認済みのセキュリティ上の懸念 (1)
機能レビュー項目 (16)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (33)
2026年7月7日 05:48
Review found no prompt-injection text or hidden malicious instructions in SKILL.md. Many static backtick and URL hits are Markdown formatting, model identifiers, placeholders, or documentation links. The remaining concerns are intentional use of the belt CLI for remote media processing and optional installation of additional third-party skills.
確認済みのセキュリティ上の懸念 (2)
機能レビュー項目 (17)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (33)
2026年7月7日 05:48
Review found no prompt-injection text or hidden malicious instructions in SKILL.md. Many static backtick and URL hits are Markdown formatting, model identifiers, placeholders, or documentation links. The remaining concerns are intentional use of the belt CLI for remote media processing and optional installation of additional third-party skills.
確認済みのセキュリティ上の懸念 (2)
機能レビュー項目 (17)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (33)
2026年6月30日 20:12
Static command and network findings are mostly true positives because the skill teaches users to run belt CLI workflows against hosted inference apps. No malicious intent, prompt injection, credential theft, or weak cryptography was found; the weak-crypto alert on SKILL.md line 3 is a false positive. Publish with a warning about external processing, shell execution, account costs, and local output files.
確認済みのセキュリティ上の懸念 (3)
静的解析の誤検知を無視 (1)
これらの静的マッチはセマンティックレビューで却下されたか、スキーマのみのトークンに一致したため、透明性のために表示されていますが、品質スコアには影響しません。
リスク要因
⚙️ 外部コマンド (17)
🌐 ネットワークアクセス (11)
📁 ファイルシステムへのアクセス (3)
検出されたパターン
2026年5月29日 09:22
This is a documentation-only skill (SKILL.md) describing how to use the inference.sh belt CLI for AI avatar video generation. All static findings are false positives: the weak crypto flag was triggered by YAML frontmatter, and the backtick executions are markdown code fence delimiters in documentation examples, not actual code execution. The hardcoded URLs are legitimate inference.sh service endpoints and documentation links.