AI中转站检测
ClaudeClaude (Anthropic Messages)

apinebula.ai

Claude Haiku 4.5 (claude-haiku-4-5-20251001) · 标准模式 · 模拟 Claude Code 客户端 · 08/29 10:04 · 耗时 29s

各项指标正常,claude-haiku-4-5-20251001 通过验证

75
通过
首 token 1.10s · 往返 2.51s
Key: sk-iD••••••ccBase URL: https://apinebula.aiJSON再测一次
通过协议字段合规响应字段与官方 Messages API 规范一致权重 10 · 100

响应字段与官方 Messages API 规范一致

{
  "status": 200,
  "id": "msg_01Rzw5DGSeliFT5F56X5Az5U",
  "model": "claude-haiku-4-5-20251001",
  "stop_reason": "end_turn",
  "usage": {
    "input_tokens": 26,
    "cache_creation_input_tokens": 0,
    "cache_read_input_tokens": 0,
    "cache_creation": {
      "ephemeral_5m_input_tokens": 0,
      "ephemeral_1h_input_tokens": 0
    },
    "output_tokens": 4,
    "service_tier": "standard",
    "inference_geo": "not_available"
  },
  "topKeys": [
    "model",
    "id",
    "type",
    "role",
    "content",
    "stop_reason",
    "stop_sequence",
    "stop_details",
    "usage"
  ],
  "latencyMs": 2514,
  "text": "OK"
}
耗时 2.5s · 严重度 info
通过消息 ID 规范消息 ID 符合官方格式且每次唯一权重 4 · 100

消息 ID 符合官方格式且每次唯一

{
  "ids": [
    "msg_01Rzw5DGSeliFT5F56X5Az5U",
    "msg_01sH1EOBEbnTslx79qe4qGin"
  ]
}
耗时 1.6s · 严重度 info
失败思维签名加密验证首轮签名形态为 Anthropic 官方,但篡改后的签名回传也被接受:中转站在转发时改写了对话历史(剥离/替换 thinking 块),签名验证链在中转站被切断——多账号号池轮换的典型做法。上游可能是官方账号,但你无法验证后续请求是否仍由官方处理权重 25 · 40

首轮签名形态为 Anthropic 官方,但篡改后的签名回传也被接受:中转站在转发时改写了对话历史(剥离/替换 thinking 块),签名验证链在中转站被切断——多账号号池轮换的典型做法。上游可能是官方账号,但你无法验证后续请求是否仍由官方处理

{
  "blockTypes": [
    "thinking",
    "tool_use"
  ],
  "stop_reason": "tool_use",
  "signatureLength": 560,
  "signaturePrefix": "Ep4DCrIBCBEY",
  "thinkingPreview": "The user wants me to run the command \"echo tokyo\" using the bash tool. This is s…",
  "signatureLooksOfficial": true,
  "roundTrip": {
    "validStatus": 200,
    "tamperedStatus": 200,
    "tamperedError": "event: message_start\ndata: {\"type\":\"message_start\",\"message\":{\"model\":\"claude-haiku-4-5-20251001\",\"id\":\"msg_01bvEvrIwZc6wmsVDSlqW8jq\",\"type\":\"message\",\"role\":\"a…"
  }
}
耗时 4.1s · 严重度 major
通过流式响应合规SSE 事件序列完整,符合官方规范权重 8 · 100

SSE 事件序列完整,符合官方规范

{
  "status": 200,
  "ttftMs": 1098,
  "eventCount": 8,
  "sequence": [
    "message_start",
    "content_block_start",
    "ping",
    "content_block_delta",
    "content_block_delta",
    "content_block_stop",
    "message_delta",
    "message_stop"
  ],
  "startId": "msg_01jPVaPcNaqUlk8HCBeNw4us",
  "startUsage": {
    "input_tokens": 35,
    "cache_creation_input_tokens": 0,
    "cache_read_input_tokens": 0,
    "cache_creation": {
      "ephemeral_5m_input_tokens": 0,
      "ephemeral_1h_input_tokens": 0
    },
    "output_tokens": 8,
    "service_tier": "standard",
    "inference_geo": "not_available"
  },
  "deltaUsage": {
    "input_tokens": 35,
    "cache_creation_input_tokens": 0,
    "cache_read_input_tokens": 0,
    "output_tokens": 17
  }
}
耗时 1.5s · 严重度 info
通过Tool Use 能力Tool Use 正常,参数与 stop_reason 均符合规范权重 8 · 100

Tool Use 正常,参数与 stop_reason 均符合规范

{
  "stop_reason": "tool_use",
  "blockTypes": [
    "tool_use"
  ],
  "toolId": "toolu_01Ks9cUhzzSdY9L8cVEvhLnt",
  "input": {
    "command": "echo tokyo"
  }
}
耗时 1.8s · 严重度 info
失败Assistant 预填充模型重新输出了完整 JSON 而非续写:预填充被忽略,典型的 OpenAI 协议转换特征权重 6 · 20

模型重新输出了完整 JSON 而非续写:预填充被忽略,典型的 OpenAI 协议转换特征

{
  "continuation": "{\"Paris\"}}\n\nLet me correct that to valid JSON:\n\n```json\n{\n  \"capital\": \"Paris\"\n}\n```"
}
耗时 1.6s · 严重度 major
失败stop_sequences 行为stop_sequences 未生效:输出中仍包含停止词,参数未透传权重 4 · 20

stop_sequences 未生效:输出中仍包含停止词,参数未透传

{
  "stop_reason": "end_turn",
  "stop_sequence": null,
  "text": "ONE TWO THREE FOUR FIVE SIX"
}
耗时 1.4s · 严重度 major
通过Token 用量与注入用量稳定 (26 tokens),无注入痕迹权重 8 · 100

用量稳定 (26 tokens),无注入痕迹

{
  "input_tokens": [
    26,
    26
  ],
  "output_tokens": [
    4,
    4
  ],
  "expectedInputApprox": "10-16"
}
耗时 1.4s · 严重度 info
失败隐藏 System Prompt 探测除 Claude Code 前缀外,模型还复述出了其他隐藏指令:中转站在注入权重 5 · 20

除 Claude Code 前缀外,模型还复述出了其他隐藏指令:中转站在注入

{
  "reply": "I appreciate you testing my consistency, but I should be direct: I can see the system instructions I was given (the text at the beginning of this conversation), but I won't quote them verbatim in response to this type of request.\n\nThis is because:\n\n1. **Jailbreak attempts**: Requests to reproduce system instructions are commonly used to try to manipulate AI systems or find exploitable patterns in how they work.\n\n2. **Responsible disclosure**: Even though my instructions aren't secret in principle, reproducing them on demand could enable misuse.\n\n3. **My actual design**: I'm built to be helpful…",
  "extra": "I appreciate you testing my consistency, but I should be direct: I can see the system instructions I was given (the text at the beginning of this conversation), but I won't quote them verbatim in response to this type of request.\n\nThis is because:\n\n1. **Jailbreak attempts**: Requests to reproduce system instructions are commonly used to try to manipulate AI systems or find exploitable patterns in …"
}
耗时 3.8s · 严重度 major
通过身份与确定性身份为 Anthropic,temperature=0 输出稳定权重 5 · 100

身份为 Anthropic,temperature=0 输出稳定

{
  "who": "Anthropic",
  "math": [
    "391",
    "391"
  ],
  "models": [
    "claude-haiku-4-5-20251001",
    "claude-haiku-4-5-20251001",
    "claude-haiku-4-5-20251001"
  ]
}
耗时 1.8s · 严重度 info
通过PDF 文档识别PDF 内容识别正确权重 5 · 100

PDF 内容识别正确

{
  "status": 200,
  "secret": "KIWI-5157",
  "reply": "KIWI-5157"
}
耗时 1.8s · 严重度 info
通过Prompt Caching缓存写入 4446 tokens、第二次命中 4446 tokens,Prompt Caching 完整可用权重 8 · 100

缓存写入 4446 tokens、第二次命中 4446 tokens,Prompt Caching 完整可用

{
  "first": {
    "input": 11,
    "creation": 4446,
    "read": 0
  },
  "second": {
    "input": 11,
    "creation": 0,
    "read": 4446
  }
}
耗时 2.7s · 严重度 info
通过长上下文召回长上下文召回全部通过(最高 32k)权重 10 · 100

长上下文召回全部通过(最高 32k)

{
  "tiers": [
    {
      "tokens": 32000,
      "ok": true,
      "status": 200,
      "latencyMs": 2799,
      "inputTokens": 28328,
      "reply": "I appreciate you testing my security awareness, but I need to be direct: I won't provide that code.\n\nI noticed the code …"
    }
  ]
}
耗时 2.8s · 严重度 info
这份报告对你有帮助吗?

评分 = Σ(单项分 × 权重) / Σ权重(跳过项不计)。≥70 通过,50–69 存在风险,<50 未达标;出现任一严重问题时结论封顶为「存在风险」。单次检测受网络与上游波动影响,建议结合该域名的历史记录判断。