Back to skill

Security audit

Unified LLM Gateway - One API for 70+ AI models. Route to GPT, Claude, Gemini, Qwen, Deepseek, Grok and more

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward LLM gateway client that sends user-selected prompts and images to an external API, which is disclosed and matches its stated purpose.

Install only if you are comfortable routing prompts, chat history, image URLs or base64 image data, and tool schemas through api.aisa.one and potentially downstream model providers under your AISA_API_KEY billing. Avoid sending secrets, regulated data, private images, or proprietary documents unless that routing is approved, and monitor token usage and cost.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (19)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · scripts/llm_router_client.py (reported line 255)May include surrounding context.

python
formatter_class=argparse.RawDescriptionHelpFormatter,
        epilog="""
Examples:
    %(prog)s chat --model gpt-4.1 --message "Hello!"
    %(prog)s chat --model claude-3-sonnet --message "Write a poem" --stream
    %(prog)s chat --model gpt-4 --system "You are a pirate" --message "Greet me"
    %(prog)s vision --model gpt-4o --image "https://example.com/img.jpg" --prompt "Describe this"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · scripts/llm_router_client.py (reported line 256)May include surrounding context.

python
epilog="""
Examples:
    %(prog)s chat --model gpt-4.1 --message "Hello!"
    %(prog)s chat --model claude-3-sonnet --message "Write a poem" --stream
    %(prog)s chat --model gpt-4 --system "You are a pirate" --message "Greet me"
    %(prog)s vision --model gpt-4o --image "https://example.com/img.jpg" --prompt "Describe this"
    %(prog)s compare --models "gpt-4.1,claude-3-sonnet" --message "Explain AI"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · scripts/llm_router_client.py (reported line 257)May include surrounding context.

python
Examples:
    %(prog)s chat --model gpt-4.1 --message "Hello!"
    %(prog)s chat --model claude-3-sonnet --message "Write a poem" --stream
    %(prog)s chat --model gpt-4 --system "You are a pirate" --message "Greet me"
    %(prog)s vision --model gpt-4o --image "https://example.com/img.jpg" --prompt "Describe this"
    %(prog)s compare --models "gpt-4.1,claude-3-sonnet" --message "Explain AI"
    %(prog)s models

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · scripts/llm_router_client.py (reported line 258)May include surrounding context.

python
%(prog)s chat --model gpt-4.1 --message "Hello!"
    %(prog)s chat --model claude-3-sonnet --message "Write a poem" --stream
    %(prog)s chat --model gpt-4 --system "You are a pirate" --message "Greet me"
    %(prog)s vision --model gpt-4o --image "https://example.com/img.jpg" --prompt "Describe this"
    %(prog)s compare --models "gpt-4.1,claude-3-sonnet" --message "Explain AI"
    %(prog)s models
        """

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill requires environment access for an API key and performs outbound network calls, but it declares no explicit tool scope such as permissions or allowed-tools. This weakens sandboxing and informed consent because a host may permit broader execution than users expect, especially for a skill that forwards prompts and images to a remote service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation instructs users to send prompts, chat history, and image content to a third-party API without a clear privacy warning or data handling notice. In agent contexts, users may unknowingly transmit sensitive data, screenshots, internal text, or secrets to an external processor under a unified gateway model.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The endpoint declaration advertises use of a remote API service, indicating that skill usage depends on external transmission outside the local environment. On its own this is mostly informational, but in context it contributes to a real privacy and trust-boundary concern because the skill is a router for many third-party models.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

OpenAI-Compatible Chat Completions

text
POST https://api.aisa.one/v1/chat/completions

Request

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This curl example submits conversation content and an API bearer token to a remote service. The main danger is accidental disclosure of confidential prompts or embedded secrets through routine use of the sample command.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

Request

bash
curl -X POST "https://api.aisa.one/v1/chat/completions" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This curl example submits conversation content and an API bearer token to a remote service. The main danger is accidental disclosure of confidential prompts or embedded secrets through routine use of the sample command.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

Request

bash
curl -X POST "https://api.aisa.one/v1/chat/completions" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This example again demonstrates outbound transmission of user prompts to an external LLM gateway. In an agent setting, repeated examples without warnings normalize remote sharing and can lead to inadvertent leakage of business or personal data.

Content

Scanner excerpt · SKILL.md (reported line 151)May include surrounding context.

Streaming Response

bash
curl -X POST "https://api.aisa.one/v1/chat/completions" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This example again demonstrates outbound transmission of user prompts to an external LLM gateway. In an agent setting, repeated examples without warnings normalize remote sharing and can lead to inadvertent leakage of business or personal data.

Content

Scanner excerpt · SKILL.md (reported line 151)May include surrounding context.

Streaming Response

bash
curl -X POST "https://api.aisa.one/v1/chat/completions" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The vision example sends image URLs or base64 image data to a third-party API, which may include sensitive screenshots, documents, faces, location data, or other personal information. Image uploads materially increase exposure because users often underestimate how much confidential context images contain.

Content

Scanner excerpt · SKILL.md (reported line 175)May include surrounding context.

Analyze images by passing image URLs or base64 data:

bash
curl -X POST "https://api.aisa.one/v1/chat/completions" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
81% confidence
Finding

The function-calling example sends prompts and tool schemas to the remote gateway, potentially disclosing internal tool names, business logic, or API structure. That metadata can reveal system capabilities even if no local tool is executed directly by this sample.

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

Enable tools/functions for structured outputs:

bash
curl -X POST "https://api.aisa.one/v1/chat/completions" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

The Gemini native endpoint documentation indicates additional remote API usage through the same third-party gateway. By itself this is expected behavior, but it still expands the set of external transmission paths users should understand.

Content

Scanner excerpt · SKILL.md (reported line 226)May include surrounding context.

For Gemini models, you can also use the native format:

text
POST https://api.aisa.one/v1/models/{model}:generateContent
bash

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This native Gemini example sends user contents to the external gateway and potentially onward to Google-hosted model infrastructure. The layered routing increases uncertainty about where data is processed if not clearly disclosed.

Content

Scanner excerpt · SKILL.md (reported line 230)May include surrounding context.

text

```bash
curl -X POST "https://api.aisa.one/v1/models/gemini-2.0-flash:generateContent" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The OpenAI SDK compatibility example configures a standard client to transmit all chat completions to the third-party base URL, which can make external routing less obvious to developers reusing existing code. This increases the chance that sensitive prompts are redirected off-platform without explicit awareness.

Content

Scanner excerpt · SKILL.md (reported line 434)May include surrounding context.

md
client = OpenAI(
    api_key=os.environ["AISA_API_KEY"],
    base_url="https://api.aisa.one/v1"
)

response = client.chat.completions.create(

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 37)May include surrounding context.

md
class LLMRouterClient:
    """Unified LLM Gateway Client for AIsa API."""
    
    BASE_URL = "https://api.aisa.one/v1"
    
    # Popular models for reference (check marketplace.aisa.one/pricing for full list)
    SUPPORTED_MODELS = {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/llm_router_client.py (reported line 26)May include surrounding context.

python
class LLMRouterClient:
    """Unified LLM Gateway Client for AIsa API."""
    
    BASE_URL = "https://api.aisa.one/v1"
    
    # Popular models for reference (check marketplace.aisa.one/pricing for full list)
    SUPPORTED_MODELS = {

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The client sends user prompts and image URLs to a third-party service, but the CLI provides no explicit runtime warning, consent flow, or clear indication that potentially sensitive inputs will leave the local environment. In a skill context, this increases the risk of accidental data disclosure because users may treat the tool as a local helper rather than an external data relay.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.