Навыки ai-video-generation История аудитов
📦

История аудитов

ai-video-generation - 6 аудиты

Сравнение версий

Изменения возможностей и находок между проверенными версиями, сначала новые.

ВерсияДатаРезультатПункты проверкиИзменение к предыдущей
v6 Последняя7 сент. 2026 г., 15:41 2 подтверждено2Возможности не изменились
v5 7 июл. 2026 г., 04:41 2 подтверждено0Возможности не изменились
v4 7 июл. 2026 г., 04:41 2 подтверждено0Возможности не изменились
v3 30 июн. 2026 г., 20:35 Подтверждённых находок нет2Возможности не изменились
v2 30 июн. 2026 г., 20:35 Подтверждённых находок нет2Возможности не изменились
v1 17 апр. 2026 г., 08:44 Подтверждённых находок нет0Базовая
Версия аудита 6 Последняя

7 сент. 2026 г., 15:41

Markdown formatting caused most command findings, and ordinary links or placeholder URLs caused most network findings. Two low-risk URLs remain confirmed, while contextual review found medium risks from unpinned installations and external media processing.

1
Просканировано файлов
253
Проанализировано строк
6
Пункты проверки
0
Ложные срабатывания проигнорированы

Подтверждённые проблемы безопасности (2)

Средний
Unpinned Remote Skill Installation
The skill recommends installations through unpinned npx and GitHub references. Mutable upstream content can change after this audit and gain agent-level capabilities.
The cited lines explicitly provide unversioned npx installation commands. No commit hash or immutable package version limits later upstream changes.
Средний
Media Disclosure to Hosted Inference Services
The belt examples submit image, audio, and video URLs to hosted inference applications. Running them may disclose sensitive media to external model providers.
The examples explicitly pass media URLs to belt app runs for remote processing. The skill does not describe local-only execution or privacy controls.
Пункты проверки возможностей (2)

Это реальные локальные возможности, которые могут ожидаться для этого навыка, поэтому они требуют проверки, но не считаются подтверждённым вредоносным поведением.

Низкий
Hardcoded URL
![AI Video Generation](https://cloud.inference.sh/app/files/u/4mg21r6ta37mpaz6ktzwtt8krr/01kg2c0egyg
The Markdown image uses a remote inference.sh asset that may trigger a third-party request when rendered. This creates a limited privacy and availability dependency.
Низкий
Hardcoded URL
> Requires inference.sh CLI (`belt`). [Install instructions](https://raw.githubusercontent.com/infer
The install guide points to mutable raw GitHub content outside the audited skill. Following changed instructions introduces a supply-chain trust dependency.
Аудитор:: codex

7 июл. 2026 г., 04:41

Static Ruby/shell backtick findings are false positives caused by Markdown inline code and fenced command examples. Hardcoded URL findings are documentation links or placeholder media URLs, not hidden network calls. The skill has medium contextual risk because it grants broad infsh CLI access and sends prompts or media URLs to external video services.

1
Просканировано файлов
186
Проанализировано строк
4
Пункты проверки
0
Ложные срабатывания проигнорированы

Подтверждённые проблемы безопасности (2)

Средний
Broad CLI Permission for External Service
The skill declares allowed-tools: Bash(infsh *), which lets the agent run any infsh subcommand. Since infsh communicates with external video services, prompts and media references may leave the user environment or incur usage costs.
The allowed-tools declaration is explicit, and the skill documents infsh app run workflows throughout SKILL.md. The risk is contextual rather than evidence of malicious intent.
Средний
External Media Processing Exposure
The examples ask users to provide image, audio, and video URLs for avatar, lipsync, upscaling, foley, and merging workflows. Private or signed media URLs could be exposed to inference.sh or model providers during normal use.
Multiple documented examples include media URL inputs sent to remote model apps. This is expected functionality, but it creates a privacy and data-handling risk for sensitive media.
Аудитор:: codex

7 июл. 2026 г., 04:41

Static Ruby/shell backtick findings are false positives caused by Markdown inline code and fenced command examples. Hardcoded URL findings are documentation links or placeholder media URLs, not hidden network calls. The skill has medium contextual risk because it grants broad infsh CLI access and sends prompts or media URLs to external video services.

1
Просканировано файлов
186
Проанализировано строк
4
Пункты проверки
0
Ложные срабатывания проигнорированы

Подтверждённые проблемы безопасности (2)

Средний
Broad CLI Permission for External Service
The skill declares allowed-tools: Bash(infsh *), which lets the agent run any infsh subcommand. Since infsh communicates with external video services, prompts and media references may leave the user environment or incur usage costs.
The allowed-tools declaration is explicit, and the skill documents infsh app run workflows throughout SKILL.md. The risk is contextual rather than evidence of malicious intent.
Средний
External Media Processing Exposure
The examples ask users to provide image, audio, and video URLs for avatar, lipsync, upscaling, foley, and merging workflows. Private or signed media URLs could be exposed to inference.sh or model providers during normal use.
Multiple documented examples include media URL inputs sent to remote model apps. This is expected functionality, but it creates a privacy and data-handling risk for sensitive media.
Аудитор:: codex

30 июн. 2026 г., 20:35

The static external command findings are true positives because the skill authorizes and documents repeated Bash calls to the infsh CLI. I found no evidence of malware or prompt injection, but the CLI sends prompts, image URLs, audio URLs, and video URLs to an external inference service, so publication should include a network data sharing warning.

1
Просканировано файлов
186
Проанализировано строк
4
Пункты проверки
1
Ложные срабатывания проигнорированы
Пункты проверки возможностей (2)

Это реальные локальные возможности, которые могут ожидаться для этого навыка, поэтому они требуют проверки, но не считаются подтверждённым вредоносным поведением.

Средний
External CLI Execution Sends User Media Data
The skill permits Bash(infsh *) and provides many infsh app run examples. This is an intended capability, but prompts and media URLs are passed to an external CLI and remote inference service, creating data disclosure and billing risk if users provide private assets.
The allowed-tools declaration and command examples directly show execution of the infsh CLI with user-provided prompts and URLs. This is legitimate for the skill purpose, but the external processing risk is clear.
Низкий
Hardcoded Documentation and Example URLs
The hardcoded URLs point to inference.sh documentation, a hosted preview image, and placeholder media examples. I did not find evidence that these URLs exfiltrate credentials or contact unrelated domains.
The URLs are visible documentation links or placeholder input URLs used in examples. They still indicate network use, but not malicious behavior.
Статические ложные срабатывания проигнорированы (1)

Эти статические совпадения были отклонены семантической проверкой или совпадали только со схемными токенами, поэтому они показываются для прозрачности, но не влияют на оценку качества.

Низкий
Weak Cryptography Static Findings Are False Positives
The static high findings at the description and table header lines do not show cryptographic operations, hashing, encryption, or credential handling. No evidence found for weak cryptographic algorithm use.
Line 3 is skill metadata text and line 63 is a markdown table header. Neither location contains executable cryptographic code or a security-sensitive algorithm.

Обнаруженные паттерны

Bash Tool Access Limited to infsh Commands
Аудитор:: codex

30 июн. 2026 г., 20:35

The static external command findings are true positives because the skill authorizes and documents repeated Bash calls to the infsh CLI. I found no evidence of malware or prompt injection, but the CLI sends prompts, image URLs, audio URLs, and video URLs to an external inference service, so publication should include a network data sharing warning.

1
Просканировано файлов
186
Проанализировано строк
4
Пункты проверки
1
Ложные срабатывания проигнорированы
Пункты проверки возможностей (2)

Это реальные локальные возможности, которые могут ожидаться для этого навыка, поэтому они требуют проверки, но не считаются подтверждённым вредоносным поведением.

Средний
External CLI Execution Sends User Media Data
The skill permits Bash(infsh *) and provides many infsh app run examples. This is an intended capability, but prompts and media URLs are passed to an external CLI and remote inference service, creating data disclosure and billing risk if users provide private assets.
The allowed-tools declaration and command examples directly show execution of the infsh CLI with user-provided prompts and URLs. This is legitimate for the skill purpose, but the external processing risk is clear.
Низкий
Hardcoded Documentation and Example URLs
The hardcoded URLs point to inference.sh documentation, a hosted preview image, and placeholder media examples. I did not find evidence that these URLs exfiltrate credentials or contact unrelated domains.
The URLs are visible documentation links or placeholder input URLs used in examples. They still indicate network use, but not malicious behavior.
Статические ложные срабатывания проигнорированы (1)

Эти статические совпадения были отклонены семантической проверкой или совпадали только со схемными токенами, поэтому они показываются для прозрачности, но не влияют на оценку качества.

Низкий
Weak Cryptography Static Findings Are False Positives
The static high findings at the description and table header lines do not show cryptographic operations, hashing, encryption, or credential handling. No evidence found for weak cryptographic algorithm use.
Line 3 is skill metadata text and line 63 is a markdown table header. Neither location contains executable cryptographic code or a security-sensitive algorithm.

Обнаруженные паттерны

Bash Tool Access Limited to infsh Commands
Аудитор:: codex

17 апр. 2026 г., 08:44

All 66 detected patterns are false positives from documentation code examples in SKILL.md. The file contains only Markdown documentation with bash code blocks showing users how to use the external inference.sh CLI tool. No executable code, command injection vectors, or active network requests exist in this skill.

1
Просканировано файлов
186
Проанализировано строк
2
Пункты проверки
0
Ложные срабатывания проигнорированы

Факторы риска

⚙️ Внешние команды (3)
🌐 Доступ к сети (3)
Аудитор:: claude