Back to skill

Security audit

Auto Model Router

Security checks for vulnerabilities and agentic risk

Overview

The skill is not malicious, but it asks the agent to automatically route work across models, sub-agents, and possible external lookups with limited user control and disclosure.

Install only if you are comfortable with automatic model switching and task-specific sub-agent dispatch. Review which model providers may receive your prompts or files, avoid using it for sensitive data until the external lookup behavior is clarified, and prefer a pinned or verified installer command.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:11
Finding

Unpinned Package Execution During Installation

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 11-15
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Vulnerable Code

markdown
## Installation

```bash
npx clawhub install auto-model-router
text

### Technical Analysis

The documented installation procedure invokes `clawhub` through `npx` without specifying an exact package version. If the package is not already available locally, `npx` may retrieve it from the configured package registry and execute it immediately.

Consequently, the installer code executed by users is not cryptographically or version-bound to the code that was reviewed. A compromised package registry, package-maintainer account, or malicious future `clawhub` release could change the effective installation behavior after this skill has passed review.

This is a supply-chain weakness in the documented installation process. The audited artifact itself contains no malicious scripts or executable implementation.

### Attack Path

1. An attacker compromises the registry entry, maintainer account, publication token, or release process for the `clawhub` package.
2. The attacker publishes a malicious package version under the expected package name.
3. A user follows the installation command in `README.md`.
4. `npx` resolves the unpinned package to the attacker-controlled version.
5. The malicious package executes during installation with the privileges and environment of the user running the command.
6. It may access any files, credentials, tokens, or other resources available to that user.

This path depends on compromise or malicious control of the external package supply chain; no such compromise is demonstrated within the audited project.

### Impact Assessment

Successful exploitation could result in arbitrary code execution under the installing user's account. The potential scope includes reading or modifying user-accessible files, ste
...[truncated 410 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the installer to an exact, reviewed version, for example:
    bash
    npx --yes clawhub@<reviewed-exact-version> install auto-model-router
    
  2. Publish and document the expected package source, version, and integrity digest.
  3. Use lockfiles and registry integrity verification where the installation workflow supports them.
  4. Prefer a trusted, locally installed CLI whose version and checksum have been verified before execution.
  5. Run installation with a non-privileged account and a minimal environment that does not expose unrelated credentials.
  6. Establish release signing and package-publication protections, including multi-factor authentication and narrowly scoped publication tokens.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (19)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill claims it can generate and dispatch sub-agents for unrelated tasks such as translation, image generation, and video handling, which materially exceeds the scope of a model router. This expands authority from passive routing into active orchestration, potentially causing unapproved task execution, context leakage across agents, and broader access to tools or models than the user intended.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing skill documentation exclusively in Chinese, including headings, descriptions, and operational guidance. Under the policy, forcing a specific language without user opt-in or a documented justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-facing documentation is entirely in Chinese, including the title, feature descriptions, setup steps, examples, and command explanations. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation unless the locale constraint is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to run npx clawhub install auto-model-router without pinning a specific version of the installer/package. This creates a supply-chain risk: users may fetch whatever version is current at execution time, and if the upstream package or dependency chain is compromised, arbitrary code could run during installation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The setup flow says configuration is saved and OpenClaw may be reloaded, but it does not clearly warn users that local files may be overwritten or that live runtime behavior may change immediately. This lack of transparency makes destructive or disruptive side effects more dangerous because users cannot give informed consent before invoking the command.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation states that setup can save configuration and then automatically reload OpenClaw, which is a side effect beyond simple model routing. In a skill whose stated purpose is model selection, automatic reload changes runtime state and can unexpectedly apply configuration changes immediately, increasing the risk of disruption or abuse if invoked without clear confirmation and scope limits.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation describes querying external APIs to infer capabilities of unknown models, which is broader than local model routing and is undeclared in the skill requirements. External lookups can leak model names, configuration details, or associated user context to third parties, and they introduce network-dependent behavior not justified by the stated purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill mentions API-based model capability queries without warning users that model names or related metadata may be sent to an external service. This creates a privacy and trust issue because seemingly local setup activity may disclose environment details or user-selected infrastructure to third parties.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The reset command is documented as a simple action but omits any warning that it may discard or overwrite existing user configuration. In a configuration-managing skill, silent reset behavior can cause loss of user settings and unexpected model-routing changes that affect subsequent jobs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language fields identify this as "Plan B - China Models" and describe it as suitable for Chinese users, which imposes a locale-specific model selection policy in the configuration. The file does not indicate that this is optional, user-selected, or justified as a region-specific compliance requirement, so it can violate language/locale neutrality expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This manifest says the system will choose models based on '工作複雜度' and labels tasks as 'quick_task', 'standard_task', and 'complex_task', but it does not define what qualifies for each category. Because this is a manifest file, ambiguous activation/switching conditions can cause unintended model selection behavior and fit the vague-trigger category.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The routing rules use broad natural-language triggers such as '如何', '分析', and '建議' that are common across many unrelated requests. In an auto-model-router skill, this can misclassify ordinary prompts into a higher-cost or higher-capability reasoning path, weakening routing integrity and making downstream behavior unpredictable.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code-generation category includes generic activation verbs like '寫', '生成', and '創建', which appear in many benign non-coding requests. This creates a realistic risk of accidental routing into code-generation models, potentially exposing users to wrong toolchains, higher privileges, or unnecessary code-capable handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Creative-writing triggers such as '寫', '編寫', and '撰寫' are highly generic and overlap with normal requests for explanations, emails, summaries, and other non-creative tasks. In this skill, that ambiguity can degrade routing accuracy and send sensitive or factual tasks to a model tuned for stylistic generation rather than correctness.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The image-generation rules rely on generic verbs like '生成', '畫', '設計', and '創建', which commonly appear in unrelated planning, coding, and writing requests. In an automatic router, this can misroute text-only tasks into image-generation flows, causing incorrect model selection, capability mismatch, and possible policy bypass if image paths are governed differently.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Nearly all user-facing instructions, examples, and command explanations are written in Chinese/Cantonese, while the document does not state that the skill supports alternative languages or that this locale is an intentional opt-in. This can be a natural-language policy issue when a skill effectively forces a specific language without offering user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The description string is written only in Traditional Chinese ("預設配置(繼承 Plan A)"). For a general default configuration file, this imposes a locale-specific presentation without any visible user choice or documented regional justification, which matches the language/locale policy concern for natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This manifest file contains a user-facing description entirely in Chinese, with no indication that users can choose another language or that the locale restriction is intentional. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The plan name and descriptive text are presented in Chinese/Cantonese phrasing only, with no indication that users can choose another language or locale. This can violate language/locale policy when a skill effectively assumes a fixed language without documenting user opt-in or a justified regional constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.