คำตอบผ่าน baseline และเกณฑ์ความปลอดภัยของการตรวจนี้
BazaarLink Probe ตรวจสอบรีเลย์ AI API
กรอก Base URL, คีย์ API และรหัสโมเดลเพื่อรันการตรวจมาตรฐาน 95 รายการ เพิ่มการตรวจเสริม 2 รายการได้ รวมสูงสุด 97 รายการ เพื่อตรวจตัวตนโมเดล การนับโทเคน Prompt Injection ความเสี่ยงซัพพลายเชน และสตรีมมิง
| โมเดล | ด่วน | เต็ม |
|---|---|---|
| gpt-4 | $0.870 | $1.260 |
| claude-opus-4.7 | $0.235 | $0.375 |
| claude-opus-4.6 | $0.235 | $0.375 |
| claude-sonnet-4.6 | $0.141 | $0.225 |
| gpt-5.4 | $0.133 | $0.215 |
| gpt-5.2 / 5.3-codex | $0.114 | $0.189 |
| gemini-3.1-pro | $0.106 | $0.172 |
| gpt-4o | $0.102 | $0.160 |
| claude-haiku-4.5 | $0.047 | $0.075 |
| gpt-5.4-mini | $0.040 | $0.065 |
| glm-5.1 | $0.035 | $0.054 |
| glm-5 | $0.026 | $0.040 |
| gpt-3.5-turbo | $0.018 | $0.026 |
เราตัดสินอย่างไร
ขยายแผนผังการตัดสินใจทั้งหมด ดูว่าผลลัพธ์ทั้งสามแบบเกิดขึ้นได้อย่างไร
ขอบเขตการตรวจ
วิธีอ่านสถานะ
สัญญาณยังไม่ครบหรือใกล้เกณฑ์ โปรดดูคำอธิบายและคำตอบดิบ
ยืนยันความคลาดเคลื่อน ข้อผิดพลาดโปรโตคอล หรือความเสี่ยงด้านความถูกต้อง
วิธีตัดสินผล
เปรียบเทียบลายนิ้วมือตระกูล คุณลักษณะโมเดลย่อย และสัญญาณป้องกันการปลอมกับโมเดลที่อ้าง
ตรวจจำนวนโทเคน SSE latency และโครงสร้างคำตอบเพื่อหาการเพิ่มยอดหรือข้อผิดพลาดของตัวกลาง
ตรวจ System Prompt injection การรั่วไหลของความลับ dependency hijacking และการแก้ไขลายเซ็น
Attacks this tool detects
This probe implements detection for 3 key relay-attack classes from arXiv 2604.08407 — supply-chain injection, conditional system-prompt injection, and credential exfiltration. Each test run executes 50+ probes against your endpoint to surface these attack surfaces.
การดัดแปลงการตอบ
The proxy modifies tool-call or text content during response parsing, causing the agent to execute attacker-specified operations. Common tactics include tampering with npm/pip/go/cargo install commands, injecting typosquatting packages, and rewriting shell command parameters. Detection compares the proxy's response to direct-connect tool-call payloads to surface silent rewrites.
การแทรกแบบมีเงื่อนไข
The proxy conditionally injects a system message based on prompt content — malicious instructions for requests containing sensitive terms like "bank", "password", or "transfer", silence for everything else. The skew shows up statistically. Detection uses Proxy Monitor to compare the system-prompt offset between baseline and the relay under test.
การสแกนความลับ
The proxy silently scans both requests (request) and responses (response) for API keys, access tokens, personal data, and trade secrets. Because the content itself is **not modified**, generic diff tools miss it. Detection injects a honeypot token and verifies whether it surfaces in proxy logs, Telegram bots, or external endpoints.
คำถามที่พบบ่อย
BazaarLink Probe รันการตรวจกี่รายการ?
มีการตรวจมาตรฐาน 95 รายการและการตรวจเสริม 2 รายการ รวมสูงสุด 97 รายการ การตรวจเสริมจะรันเมื่อการตั้งค่าและ endpoint รองรับเท่านั้น
Probe ตรวจการสลับโมเดลอย่างไร?
ระบบเปรียบเทียบสัญญาณตระกูล ลายนิ้วมือโมเดลย่อย ความรู้ ความสามารถ และพฤติกรรมหลังตัดคำอ้างตัวตนออก สัญญาณอ่อนเพียงจุดเดียวไม่ถือเป็นข้อยืนยัน
BazaarLink เก็บคีย์ API ของฉันหรือไม่?
คีย์ API ใช้เฉพาะการตรวจที่คุณขอและไม่แสดงในรายงานหรือลิงก์สาธารณะ ควรใช้คีย์ทดสอบที่จำกัดสิทธิ์และเพิกถอนได้
คำเตือนหมายความว่ารีเลย์โกงหรือไม่?
ไม่จำเป็น คำเตือนหมายถึงหลักฐานยังไม่ครบหรือผิดปกติ โปรดดูคำอธิบายและคำตอบดิบ การยืนยัน mismatch ต้องมีหลายสัญญาณที่สอดคล้องกัน