Back to skill

Security audit

Router NIMIMORE

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small local model-selection helper with no evidence of hidden execution, persistence, credential access, or data exfiltration.

Installers should treat this as a local routing helper, not as a full model gateway. Review the provider names it may select, especially for sensitive prompts, because downstream use of the selected model could involve sending content to Moonshot or Bailian even though this package itself does not make network calls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises automatic routing across multiple external AI providers but does not warn users that their prompts and possibly surrounding context will be transmitted off-platform. This creates a real privacy and data-governance risk because users may submit sensitive content under the assumption processing is local or provider-neutral, especially since the skill emphasizes convenience and 'works out of the box' behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This is a natural-language policy issue because the file includes user-facing descriptive text in Chinese alongside the tool identity, but does not indicate that Chinese is optional or that the skill is intentionally region-specific. A skill that effectively assumes a specific language without opt-in can violate organizational language/locale policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The usage examples and routing logic consistently present Chinese queries, which can signal an implicit language expectation for the skill. Because the README does not state that the skill is China/Chinese-specific or that other languages are equally supported, this may conflict with a language/locale neutrality policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The supported-model table states 'bailian/qwen-max' is for 'Code & Chinese,' which implies language-based steering to a particular provider without explaining the policy or offering user choice. While not inherently malicious, opaque locale-based routing can raise fairness, privacy, and compliance concerns if users are silently routed based on language characteristics they did not consent to.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file includes user-facing natural-language content in Chinese, such as the docstring and test queries/descriptions, but provides no indication that the skill is intentionally Chinese-only or that users can opt into another language. That creates a language/locale policy concern under the natural-language policy rule because the file implicitly assumes a specific language without documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.