审计历史
qwen-image-pro - 2 审计
审计版本 2
最新 安全Mar 6, 2026, 08:49 AM
All static findings are false positives. The skill uses the legitimate inference.sh CLI tool to access Alibaba Qwen-Image-2.0-Pro API for image generation. External command detections are documentation examples, network URLs are legitimate service endpoints, and cryptographic algorithm warnings are scanner misinterpretations. No actual security vulnerabilities present.
高风险问题 (1)
中风险问题 (1)
低风险问题 (1)
风险因素
⚙️ 外部命令 (1)
🌐 网络访问 (1)
审计版本 1
安全Mar 5, 2026, 08:56 AM
All 56 static findings are false positives. The skill file contains only markdown documentation with code examples showing how to use the inference.sh CLI. The detected patterns (shell commands, URLs) appear in fenced code blocks as legitimate documentation examples. No executable code, prompt injection attempts, or malicious intent detected. Safe to publish.