Back to skill

Security audit

Auto Model Router

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent model-routing helper, but it can automatically change which model/provider handles tasks and persist/reload routing settings without enough disclosure or user control.

Install only if you are comfortable with OpenClaw automatically choosing among multiple model providers for your tasks. Review the Plan A/Plan B providers, avoid routing sensitive prompts or files to providers you have not approved, back up existing routing configuration before setup or reset, and prefer a pinned/verified clawhub installer rather than the unpinned npx command shown in the README.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:14
Finding

Unpinned Package Execution in Installation Instructions

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 14-17
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code:

bash
## Installation

npx clawhub install auto-model-router

Technical Analysis

The documented installation command invokes clawhub through npx without specifying a package version or integrity value. If the package is not already available locally, npx can retrieve and execute the currently resolved release from the configured npm registry.

Because the project provides no lockfile, integrity hash, vendored executable, or pinned CLI version, the code executed during installation can differ from the code originally reviewed. This creates a supply-chain trust boundary outside the audited repository. Exploitation would require compromise, substitution, or malicious publication of the package resolved as clawhub; the repository itself does not contain evidence that the current package is malicious.

Attack Path

  1. An attacker compromises the npm account, package publication process, registry resolution, or another relevant distribution channel for the package resolved as clawhub.
  2. The attacker publishes or causes resolution to a malicious release containing lifecycle scripts or malicious CLI behavior.
  3. A user follows the installation command from README.md.
  4. npx downloads and executes the unpinned package.
  5. The malicious package runs with the privileges and environment access of the user executing the command.

Impact Assessment

Successful exploitation could permit arbitrary code execution under the installing user's account. Depending on that account's privileges and environment, the malicious package could read or modify accessible files, steal environment variables or developer credentials, alter local configuration, install additional payloads, or tamper with other projects.

The impact is normally limited to the ...[truncated 281 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to a specifically reviewed release, for example:
    bash
    npx clawhub@<reviewed-version> install auto-model-router
    
  2. Verify the selected release against an expected package integrity hash or signed provenance before execution.
  3. Document the authoritative package name, publisher, registry, and release source so users can detect typosquatting or registry substitution.
  4. Prefer installing a verified, pinned CLI separately and invoking that trusted local installation rather than allowing installation-time resolution of the latest release.
  5. Use lockfiles and reproducible dependency controls where the installation workflow permits them.
  6. In controlled environments, disable network package resolution during invocation and use a previously verified local package cache.
  7. Warn users not to execute the installation process with administrative privileges unless strictly required.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (16)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document describes automatic routing of user tasks across multiple third-party model providers, including fallback behavior for unknown tasks and models, but does not warn that user prompts, files, or derived content may be transmitted to external services. In a routing skill, this omission is security-relevant because users may unknowingly expose sensitive data to additional vendors beyond the one they expected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description and all user-facing instructions are written in Chinese, and there is no indication that users may choose another language or that the skill is intended only for a Chinese-speaking or region-specific audience. This can violate a language/locale policy when skills must not force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The README instructs users to run npx clawhub install auto-model-router without pinning a specific package version. This can cause users to execute whatever version is currently published, increasing supply-chain risk if the package is updated maliciously, compromised, or changed incompatibly. In a setup/install command, this is more dangerous because users are likely to copy-paste it directly into a shell.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language content of the skill is predominantly Chinese/Cantonese, while the file does not state that the skill is region-specific or provide an opt-in language choice. This can violate language/locale policy when users are implicitly forced into a specific language without consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documented setup flow explicitly says it will save configuration and automatically reload OpenClaw, but it does not warn users that this can overwrite existing routing settings or immediately change runtime behavior. In a skill that controls model selection and sub-agent dispatch, silent persistence and reloads can cause unintended configuration loss or unexpected execution under different models.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The reset command is listed without any warning that it may discard customized model-routing settings and revert behavior across all task categories. Because this skill influences automatic model routing, a reset can have broad operational impact and may surprise users into losing carefully tuned or safer configurations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description says the skill will 'automatically select the best model based on task complexity' without stating when it should activate, what inputs it inspects, or what guardrails limit routing behavior. Broad auto-activation language can cause the skill to engage outside intended contexts, leading to unexpected model selection, policy bypass of user preferences, or unintended disclosure of task content to different backends.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description states this plan is 'suitable for Chinese users,' which encodes a locale-specific preference in natural language. Under the policy, locale constraints should either offer user opt-in or be clearly documented as a justified region-specific requirement; that justification is not present in this file.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The routing rules use very broad verbs such as '寫', '生成', '創建', and '開發' across multiple categories, creating overlapping triggers that can misclassify user tasks. In an auto-model-router skill, this can route prompts to weaker or less appropriate models, causing policy bypass opportunities, degraded output quality, or unexpected capability selection.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The creative-writing category contains generic activation terms like '寫', '編寫', and '撰寫' that apply to many non-creative tasks, including code, analysis, and structured document generation. Because this skill automatically selects models, such ambiguity can be exploited by phrasing a request to force creative-routing behavior and avoid the model best suited for safer or more accurate task handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The image-generation rules include broad verbs like '生成', '畫', '設計', and '創建', which are common across unrelated tasks and can easily overmatch. In a model router, this increases the risk of dispatching ordinary text or planning requests to image-capable models, potentially exposing unnecessary capabilities or causing incorrect downstream behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

A skill document that presents all instructions and behavior descriptions in a single language can create a language-policy issue when no user choice or locale justification is provided. Here, the file uses Chinese throughout and does not mention that the skill is Chinese-only, region-specific, or selectable by user preference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The description references 'Plan A (International) and Plan B (China) model configurations' in a way that suggests locale- or region-specific routing is built in, but it does not mention user consent, transparency, or selection controls. If routing is based on geography or inferred locale, users may be silently directed to different model stacks with different data handling, compliance, or censorship characteristics.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The description field is written only in Traditional Chinese ("預設配置(繼承 Plan A)"), which may impose a language choice on users without offering an alternative or opt-in. This matches the policy category for language or locale constraints that are not documented as optional or region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This manifest contains user-facing natural-language text in Chinese only, which can impose a language/locale choice without user opt-in. The file does not indicate that the skill is region-specific or that alternate language options are available.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The natural-language labels, descriptions, and trigger values throughout the file are exclusively in Chinese, which effectively imposes a single language/locale in the skill configuration. There is no indication of user opt-in, multilingual support, or a documented reason that the skill is intended to be Chinese-only.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.