审计历史
faceswap - 3 审计
审计版本 3
最新 中风险Jun 8, 2026, 11:50 AM
The skill is a documentation/instruction file (no executable code) that guides an AI assistant to run shell commands (yt-dlp, ffmpeg, curl) and make API calls to verging.ai. All 82 static findings are false positives in context: backtick patterns are markdown code examples, URLs are legitimate API endpoints, API key references are standard authentication documentation, and temp directory access is standard media processing. The combination of network + credentials + external commands is expected for this use case. No malicious intent detected. Risk level is medium due to the breadth of system access required.
中风险问题 (1)
低风险问题 (4)
风险因素
⚙️ 外部命令 (5)
🌐 网络访问 (5)
🔑 环境变量 (3)
📁 文件系统访问 (3)
审计版本 2
安全Mar 18, 2026, 06:56 AM
This is a legitimate face swap API client skill. The static findings reflect expected behavior: network calls to the verging.ai API service, environment variable access for API key authentication, and external command execution for video processing tools (yt-dlp, ffmpeg, curl). These are all necessary for the skill's core functionality. No malicious intent detected.
风险因素
🌐 网络访问 (18)
🔑 环境变量 (16)
⚙️ 外部命令 (36)
📁 文件系统访问 (3)
审计版本 1
低风险Mar 17, 2026, 04:11 PM
Static analysis flagged 77 patterns but all are false positives. Network URLs point to documented verging.ai API endpoints. Environment variable access is for user-provided API key authentication. Shell commands in SKILL.md are markdown documentation examples, not executable code. Temp directory usage is documented with cleanup. Skill is a legitimate CLI wrapper for a paid AI service.