Historique des audits
faceswap - 3 audits
Version de l’audit 3
Dernier Risque moyenJun 8, 2026, 11:50 AM
The skill is a documentation/instruction file (no executable code) that guides an AI assistant to run shell commands (yt-dlp, ffmpeg, curl) and make API calls to verging.ai. All 82 static findings are false positives in context: backtick patterns are markdown code examples, URLs are legitimate API endpoints, API key references are standard authentication documentation, and temp directory access is standard media processing. The combination of network + credentials + external commands is expected for this use case. No malicious intent detected. Risk level is medium due to the breadth of system access required.
Problèmes à risque moyen (1)
Problèmes à risque faible (4)
Facteurs de risque
⚙️ Commandes externes (5)
🌐 Accès réseau (5)
🔑 Variables d’environnement (3)
📁 Accès au système de fichiers (3)
Version de l’audit 2
SûrMar 18, 2026, 06:56 AM
This is a legitimate face swap API client skill. The static findings reflect expected behavior: network calls to the verging.ai API service, environment variable access for API key authentication, and external command execution for video processing tools (yt-dlp, ffmpeg, curl). These are all necessary for the skill's core functionality. No malicious intent detected.
Facteurs de risque
🌐 Accès réseau (18)
🔑 Variables d’environnement (16)
⚙️ Commandes externes (36)
📁 Accès au système de fichiers (3)
Version de l’audit 1
Risque faibleMar 17, 2026, 04:11 PM
Static analysis flagged 77 patterns but all are false positives. Network URLs point to documented verging.ai API endpoints. Environment variable access is for user-provided API key authentication. Shell commands in SKILL.md are markdown documentation examples, not executable code. Temp directory usage is documented with cleanup. Skill is a legitimate CLI wrapper for a paid AI service.