Back to skill

Security audit

LLM Router Gateway

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward LLM gateway skill that sends user-chosen prompts, images, and model requests to the documented AIsa API.

Install only if you intend to send prompts, message histories, image URLs or base64 images, and tool/function schemas to AIsa and possibly downstream model providers. Do not use it with secrets, regulated data, internal signed URLs, or confidential documents unless that data sharing is approved.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (20)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · scripts/llm_router_client.py (reported line 255)May include surrounding context.

python
formatter_class=argparse.RawDescriptionHelpFormatter,
        epilog="""
Examples:
    %(prog)s chat --model gpt-4.1 --message "Hello!"
    %(prog)s chat --model claude-3-sonnet --message "Write a poem" --stream
    %(prog)s chat --model gpt-4 --system "You are a pirate" --message "Greet me"
    %(prog)s vision --model gpt-4o --image "https://example.com/img.jpg" --prompt "Describe this"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · scripts/llm_router_client.py (reported line 256)May include surrounding context.

python
epilog="""
Examples:
    %(prog)s chat --model gpt-4.1 --message "Hello!"
    %(prog)s chat --model claude-3-sonnet --message "Write a poem" --stream
    %(prog)s chat --model gpt-4 --system "You are a pirate" --message "Greet me"
    %(prog)s vision --model gpt-4o --image "https://example.com/img.jpg" --prompt "Describe this"
    %(prog)s compare --models "gpt-4.1,claude-3-sonnet" --message "Explain AI"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · scripts/llm_router_client.py (reported line 257)May include surrounding context.

python
Examples:
    %(prog)s chat --model gpt-4.1 --message "Hello!"
    %(prog)s chat --model claude-3-sonnet --message "Write a poem" --stream
    %(prog)s chat --model gpt-4 --system "You are a pirate" --message "Greet me"
    %(prog)s vision --model gpt-4o --image "https://example.com/img.jpg" --prompt "Describe this"
    %(prog)s compare --models "gpt-4.1,claude-3-sonnet" --message "Explain AI"
    %(prog)s models

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

The vision example encourages users to submit an image URL to a remote API without warning that the URL and associated prompt will be disclosed externally and may cause downstream fetching by third-party systems. In a skill environment, this is more dangerous because users may provide internal, signed, or sensitive URLs, leading to unintended exposure of private resources or metadata.

Content

Scanner excerpt · scripts/llm_router_client.py (reported line 258)May include surrounding context.

python
%(prog)s chat --model gpt-4.1 --message "Hello!"
    %(prog)s chat --model claude-3-sonnet --message "Write a poem" --stream
    %(prog)s chat --model gpt-4 --system "You are a pirate" --message "Greet me"
    %(prog)s vision --model gpt-4o --image "https://example.com/img.jpg" --prompt "Describe this"
    %(prog)s compare --models "gpt-4.1,claude-3-sonnet" --message "Explain AI"
    %(prog)s models
        """

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill explicitly requires environment access for AISA_API_KEY and demonstrates network calls to api.aisa.one, but it does not declare any tool scope such as permissions or allowed-tools. This creates a governance gap: an agent or reviewer cannot easily understand or constrain the skill's capability to read secrets and transmit data externally.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This example performs an authenticated POST to an external service and transmits user-supplied prompt content off-platform. The behavior is expected for an API client, but it is still security-relevant because it can disclose sensitive text and associated metadata to a third party.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

Request

bash
curl -X POST "https://api.aisa.one/v1/chat/completions" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This example performs an authenticated POST to an external service and transmits user-supplied prompt content off-platform. The behavior is expected for an API client, but it is still security-relevant because it can disclose sensitive text and associated metadata to a third party.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

Request

bash
curl -X POST "https://api.aisa.one/v1/chat/completions" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The examples instruct users to send prompts and, elsewhere in the skill, images to a third-party LLM gateway without any privacy notice, data handling warning, or mention that content may be processed by downstream model providers. In an agent setting, users may unknowingly transmit sensitive prompts, files, or image-derived data outside their trust boundary.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The streaming example sends prompt data to an external API endpoint using a bearer token, creating the same confidentiality exposure as the non-streaming example. Streaming can also increase accidental disclosure in logs or terminal sessions because partial outputs are emitted continuously.

Content

Scanner excerpt · SKILL.md (reported line 151)May include surrounding context.

Streaming Response

bash
curl -X POST "https://api.aisa.one/v1/chat/completions" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The streaming example sends prompt data to an external API endpoint using a bearer token, creating the same confidentiality exposure as the non-streaming example. Streaming can also increase accidental disclosure in logs or terminal sessions because partial outputs are emitted continuously.

Content

Scanner excerpt · SKILL.md (reported line 151)May include surrounding context.

Streaming Response

bash
curl -X POST "https://api.aisa.one/v1/chat/completions" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The vision example sends image URLs or base64 image data to a third-party LLM endpoint, which can expose highly sensitive visual content, embedded metadata, or internal resource locations. Because images often contain PII, documents, screenshots, or secrets, the context makes this more dangerous than a simple text prompt example.

Content

Scanner excerpt · SKILL.md (reported line 175)May include surrounding context.

Analyze images by passing image URLs or base64 data:

bash
curl -X POST "https://api.aisa.one/v1/chat/completions" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The function-calling example transmits user prompts and tool schema definitions to an external API. While function schemas are often harmless, they can reveal internal capabilities, business logic, or integration details if copied from production agents.

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

Enable tools/functions for structured outputs:

bash
curl -X POST "https://api.aisa.one/v1/chat/completions" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The Gemini-format curl example performs authenticated external transmission of user content to the same third-party service. Although normal for an API integration, it still creates data-sharing and confidentiality risk, especially since model routing may involve additional downstream providers.

Content

Scanner excerpt · SKILL.md (reported line 230)May include surrounding context.

text

```bash
curl -X POST "https://api.aisa.one/v1/models/gemini-2.0-flash:generateContent" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The OpenAI SDK compatibility example reconfigures a standard client to send requests and prompts to api.aisa.one, which could be mistaken for equivalent local/OpenAI handling by users who focus only on SDK syntax. This increases the chance of accidental third-party disclosure because the code makes redirection seamless.

Content

Scanner excerpt · SKILL.md (reported line 434)May include surrounding context.

md
client = OpenAI(
    api_key=os.environ["AISA_API_KEY"],
    base_url="https://api.aisa.one/v1"
)

response = client.chat.completions.create(

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 37)May include surrounding context.

md
class LLMRouterClient:
    """Unified LLM Gateway Client for AIsa API."""
    
    BASE_URL = "https://api.aisa.one/v1"
    
    # Popular models for reference (check marketplace.aisa.one/pricing for full list)
    SUPPORTED_MODELS = {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

md
class LLMRouterClient:
    """Unified LLM Gateway Client for AIsa API."""
    
    BASE_URL = "https://api.aisa.one/v1"
    
    # Popular models for reference (check marketplace.aisa.one/pricing for full list)
    SUPPORTED_MODELS = {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 226)May include surrounding context.

md
class LLMRouterClient:
    """Unified LLM Gateway Client for AIsa API."""
    
    BASE_URL = "https://api.aisa.one/v1"
    
    # Popular models for reference (check marketplace.aisa.one/pricing for full list)
    SUPPORTED_MODELS = {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/llm_router_client.py (reported line 26)May include surrounding context.

python
class LLMRouterClient:
    """Unified LLM Gateway Client for AIsa API."""
    
    BASE_URL = "https://api.aisa.one/v1"
    
    # Popular models for reference (check marketplace.aisa.one/pricing for full list)
    SUPPORTED_MODELS = {

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI sends user prompts, full message histories, and image URLs to a third-party API endpoint, but provides no explicit warning, consent prompt, or clear disclosure at the point of use. In a skill context, this creates a real data exfiltration/privacy risk because users may pass sensitive text or internal URLs assuming the tool operates locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill tells users to export AISA_API_KEY but does not warn that this credential is sensitive or should not be echoed, logged, committed, or shared with model prompts. While common in setup docs, omission of credential-handling guidance increases the risk of accidental exposure in agent logs or shell history.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.