Back to skill

Security audit

Evez Api Gateway

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward third-party AI API client, with the main risk being that user prompts and image URLs are sent to EVEZ's remote service.

Install this only if you are comfortable routing prompts, outputs, and image URLs through EVEZ rather than the original model provider. Do not send secrets, regulated data, private customer content, or internal image URLs without reviewing EVEZ's data handling and compliance terms.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs users to send OpenAI-compatible requests to a third-party endpoint, which means prompts, outputs, and potentially sensitive application data will be transmitted off-platform. Because the skill presents this as a drop-in replacement focused on cost savings without any privacy, security, retention, or trust-boundary warning, users may unknowingly route confidential data to an unvetted service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The chat() method sends user message content to a remote API endpoint, and the code provides no confirmation prompt, logging, or explanatory comment disclosing that user input is transmitted off-system. For a client wrapper, this data transfer is safety-relevant because prompts may contain sensitive user or system information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The vision() method transmits both user-supplied text and an image URL to the remote EVEZ API, but the file contains no warning, comment, or prompt explaining that this information leaves the local environment. This is especially relevant because image URLs can reveal private resources or internal locations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.