FEATUREDAI HOT (Curated Pool)· aihot-apiZH00:42 · 05·18
→Open-source tool exposes security risks and detection gaps in AI API relays
api-relay-audit audits AI API relay risks with verifiable three-state decisions and transparent logs, covering AC-1 tool-call rewriting, AC-2 error-response leakage, and context truncation, while the author has published the methodology, comparison results, quick-reference table, and the open-source tool.
#Tools#Safety#Benchmarking#api-relay-audit
why featured
Featured · importance 76 · hook + knowledge + resonance
editor take
API relays finally get a test harness; I care less about the transparency claim and more about whether the logs reproduce across vendors.
sharp
api-relay-audit moves API relay risk from accusation to reproducible probing, which is the useful part here. The concrete checks are AC-1 tool-call rewriting, AC-2 error-response leakage, and context truncation, with three-state decisions and transparent logs. Those are exactly the places a relay can tamper with model behavior while leaving users with weak evidence.
I discount the claim that it is more reliable than hvoy.ai or cctest.ai for now. The snippet says the author published methodology, comparison results, a quick-reference table, and the open-source tool. It does not give sample size, false-positive rate, number of relays tested, or whether a third party can rerun the logs. A safety benchmark without replayable evidence quickly becomes another trust proxy.
HKR breakdown
hook ✓knowledge ✓resonance ✓