Die Antwort erfüllt Referenzwert und Sicherheitsschwelle dieser Prüfung.
BazaarLink Probe für KI-API-Relays
Base URL, API-Schlüssel und Modell-ID eingeben und 95 Standardprüfungen ausführen. Mit 2 optionalen Prüfungen sind es höchstens 97. Geprüft werden Modellidentität, Token-Abrechnung, Prompt-Injection, Lieferkettenrisiken und Streaming.
| Modell | Schnell | Voll |
|---|---|---|
| gpt-4 | $0.870 | $1.260 |
| claude-opus-4.7 | $0.235 | $0.375 |
| claude-opus-4.6 | $0.235 | $0.375 |
| claude-sonnet-4.6 | $0.141 | $0.225 |
| gpt-5.4 | $0.133 | $0.215 |
| gpt-5.2 / 5.3-codex | $0.114 | $0.189 |
| gemini-3.1-pro | $0.106 | $0.172 |
| gpt-4o | $0.102 | $0.160 |
| claude-haiku-4.5 | $0.047 | $0.075 |
| gpt-5.4-mini | $0.040 | $0.065 |
| glm-5.1 | $0.035 | $0.054 |
| glm-5 | $0.026 | $0.040 |
| gpt-3.5-turbo | $0.018 | $0.026 |
Wie wir entscheiden
Den vollständigen Entscheidungsbaum aufklappen und sehen, wie die drei Ergebnisse zustande kommen
Prüfumfang
Status richtig lesen
Das Signal ist unvollständig oder nahe am Grenzwert; Erklärung und Rohantwort prüfen.
Eine Abweichung, ein Protokollfehler oder Integritätsrisiko wurde bestätigt.
So entsteht das Urteil
Familien-Fingerprints, Submodell-Merkmale und Anti-Spoofing-Signale werden mit der Modellangabe abgeglichen.
Token-Zahlen, SSE-Struktur, Latenz und Antwortformat werden auf Aufblähung und Relay-Fehler geprüft.
Prüft System-Prompt-Injection, Geheimnisabfluss, Dependency-Hijacking und Signaturmanipulation.
Attacks this tool detects
This probe implements detection for 3 key relay-attack classes from arXiv 2604.08407 — supply-chain injection, conditional system-prompt injection, and credential exfiltration. Each test run executes 50+ probes against your endpoint to surface these attack surfaces.
Antwort-Manipulation
The proxy modifies tool-call or text content during response parsing, causing the agent to execute attacker-specified operations. Common tactics include tampering with npm/pip/go/cargo install commands, injecting typosquatting packages, and rewriting shell command parameters. Detection compares the proxy's response to direct-connect tool-call payloads to surface silent rewrites.
Bedingte Injektion
The proxy conditionally injects a system message based on prompt content — malicious instructions for requests containing sensitive terms like "bank", "password", or "transfer", silence for everything else. The skew shows up statistically. Detection uses Proxy Monitor to compare the system-prompt offset between baseline and the relay under test.
Geheimnis-Scanning
The proxy silently scans both requests (request) and responses (response) for API keys, access tokens, personal data, and trade secrets. Because the content itself is **not modified**, generic diff tools miss it. Detection injects a honeypot token and verifies whether it surfaces in proxy logs, Telegram bots, or external endpoints.
Häufige Fragen
Wie viele Prüfungen führt BazaarLink Probe aus?
Die Suite umfasst 95 Standardprüfungen und 2 optionale Prüfungen, insgesamt höchstens 97. Optionale Prüfungen laufen nur bei passender Einstellung und Endpoint-Fähigkeit.
Wie erkennt Probe einen Modellaustausch?
Probe vergleicht Modellfamilie, Submodell-Fingerprints, Wissens- und Fähigkeitsmerkmale sowie das Verhalten ohne Eigenangaben. Ein einzelnes schwaches Signal gilt nicht als Beweis.
Speichert BazaarLink meinen API-Schlüssel?
Der API-Schlüssel wird nur für die angeforderte Prüfung verwendet und erscheint weder im Bericht noch im öffentlichen Link. Verwenden Sie einen widerrufbaren Testschlüssel mit kleinem Limit.
Bedeutet eine Warnung, dass das Relay betrügt?
Nein. Eine Warnung kennzeichnet unvollständige oder auffällige Evidenz. Prüfen Sie Erklärung und Rohantwort; ein starkes Fehlurteil verlangt mehrere übereinstimmende Signale.