Back to skill

Security audit

LLM Router

Security checks for vulnerabilities and agentic risk

Overview

This skill matches its stated LLM routing purpose and only uses an AIsa API key to send requested model calls to AIsa.

Before installing, make sure you trust AIsa with the prompts, image URLs, and usage tied to your AISA_API_KEY. Use a scoped or revocable key if available and avoid sending sensitive content unless AIsa's data handling terms are acceptable to you.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.