Back to skill

Security audit

Auto Model Router

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent model router, but it gives itself broad automatic routing, sub-agent, persistence, and reload behavior without enough user control or data-sharing disclosure.

Review before installing. Use it only if you are comfortable with automatic model/provider switching and possible sharing of prompts or files with the selected providers. Prefer a pinned installer version, choose an allowed provider/region plan explicitly, disable or confirm sub-agent creation where possible, and confirm before saving config or reloading OpenClaw.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:13
Finding

Unpinned Third-Party CLI Execution During Installation

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 13–17
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code

markdown
## Installation

```bash
npx clawhub install auto-model-router
text

### Technical Analysis

The documented installation procedure invokes the third-party `clawhub` npm package through `npx` without specifying a version, package integrity hash, trusted registry, or lockfile.

When the package is not already available locally, `npx` may retrieve the currently resolved package release and execute its CLI code. Consequently, the code executed by users can differ from the code that was available when this Skill was audited. This creates a mutable supply-chain boundary outside the reviewed project.

The project itself contains no malicious scripts or executable payloads. The risk arises from instructing users to execute an unpinned external package whose future contents cannot be established from this repository.

### Attack Path

1. An attacker compromises the npm account, publication pipeline, registry resolution, or another relevant distribution component for the `clawhub` package.
2. The attacker publishes a malicious or backdoored package release that satisfies unversioned resolution.
3. A user follows the installation instructions and runs:
   ```bash
   npx clawhub install auto-model-router
   ```
4. `npx` resolves and downloads the attacker-controlled release.
5. The malicious CLI or applicable package lifecycle behavior executes with the privileges of the invoking user.

### Impact Assessment

Successful exploitation could allow arbitrary code execution under the installing user's account. Depending on that account's permissions and environment, the malicious package could access user-readable files, modify user configuration, steal credentials available to the process, install additional components, or alter the Open
...[truncated 302 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the installer to a specifically reviewed release:
    bash
    npx clawhub@<verified-version> install auto-model-router
    
  2. Publish the expected npm registry, package identity, version, and integrity digest in the installation documentation.
  3. Prefer installing the CLI as a project dependency governed by a committed lockfile, then invoke the locked local binary.
  4. Disable or minimize package lifecycle scripts where the installation workflow supports doing so.
  5. Verify package provenance and signatures before execution, and document a trusted release-verification procedure.
  6. Run installation with least privilege in an isolated environment rather than from an administrator or root account.
  7. Periodically review and deliberately update the pinned version instead of automatically resolving the latest release.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (20)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Automatic generation and dispatch of translator, image, and video sub-agents is unjustified for a routing skill and meaningfully increases autonomy. In context, this is dangerous because delegated agents may process additional user content, switch models silently, and perform unrelated operations without a clear user approval boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document describes automatic model routing across multiple third-party providers, including fallback behavior, but does not warn that user prompts, uploaded content, or task data may be transmitted to external services. In a routing skill, this omission is security-relevant because users may unknowingly send sensitive data to different vendors depending on classification or fallback decisions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description is presented in Chinese and does not indicate that other languages are supported or that the language choice is optional. Under the policy, a skill should not impose a specific language or locale unless it offers opt-in choice or clearly documents a justified regional constraint.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The README instructs users to execute npx clawhub install auto-model-router without pinning a specific version of the package. This can lead to installation of a newer or compromised release than the author intended, increasing supply-chain risk if the package or one of its transitive dependencies is malicious or hijacked.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill description and instructions are presented entirely in Chinese/Cantonese, and one feature specifically highlights Cantonese voice support, but there is no statement that users may choose another language. This can be a natural-language policy issue when a skill appears to impose a language/locale without opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is presented as a model-routing helper, but the documented behavior also persists configuration to disk and triggers an OpenClaw reload. That expands scope from advisory routing into state-changing system actions, which can surprise users and create integrity or availability risk if invoked without explicit consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation does not clearly warn users that configuration will be written to disk and that the system may reload OpenClaw. Missing disclosure of persistent changes and service reloads can lead to uninformed consent, accidental configuration changes, or temporary disruption of active workflows.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation extends a model-router into spawning sub-agents that execute separate tasks such as translation, image generation, and video handling. This is a material scope expansion that can cause unintended autonomous actions, broaden permissions and data exposure, and make the actual behavior much riskier than users would expect from a routing skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill claims to route models, but it also proposes querying unknown model capabilities via a local database or external API. That introduces undeclared data flows and network behavior beyond routing, with potential privacy leakage if user-supplied model names or context are sent externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill describes automatic model-capability lookup via API without a privacy warning. Even if the queried data seems limited, undocumented outbound requests can expose user preferences, internal model names, or enterprise usage patterns to third parties.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The description hard-codes region-based routing categories, 'Plan A (International)' and 'Plan B (China)', without indicating user awareness, consent, or selection criteria. In a model-routing skill, region-based defaults can create data-governance, privacy, and compliance risk by implicitly sending prompts to different infrastructure or jurisdictions based on undisclosed logic.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The plan name and description explicitly define this configuration as a China-specific model package for Chinese users. This constitutes a locale-targeted policy choice in natural language, but the file does not indicate any user choice, opt-in, or documented justification beyond suitability for Chinese users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The plan name and descriptive text are written entirely in Chinese/Cantonese-oriented phrasing, including expressions like "懶人模式" and "最啱嘅", with no indication that users can select another language or locale. The policy requires flagging language or locale constraints when they are imposed without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The natural-language descriptions, category names, keywords, and input patterns are entirely Chinese/Cantonese-oriented, which indicates the skill is tailored to a specific language/locale. The file does not state that this is optional, user-selected, or justified as a region-specific tool, so it may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The routing rules use very broad and generic trigger terms such as verbs like '分析', '如何', '寫', and '生成', which can match many unrelated requests. In an auto-model-router skill, this can cause systematic misclassification and route user prompts to an unintended model class, leading to degraded safety controls, privacy boundary mismatches, or incorrect downstream tool/model behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Several categories contain overlapping patterns like '分析', '寫', '生成', and '創建', but the file does not define clear disambiguation logic or exclusivity constraints. This ambiguity is risky in a model-routing component because attackers or ordinary users can craft prompts that trigger multiple buckets and steer execution toward a less appropriate or less constrained model path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The file presents separate international and domestic model plans, but the discussion does not clearly bind selection to explicit user choice or consent at the point of routing. In practice, this can normalize locale- or policy-based provider switching without transparent opt-in, which raises privacy and compliance concerns when different jurisdictions or vendors are involved.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This manifest description is broad and does not specify when the routing behavior should apply, what inputs trigger it, or any exclusions. In a manifest file, lack of trigger specificity can lead to unintended or overly broad invocation by systems that rely on the description text.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The description text is written only in Traditional Chinese ("預設配置(繼承 Plan A)"), which may indicate a language-specific default without any visible user choice or opt-in. Under the policy rule, locale or language constraints should be explicitly optional or justified when they are imposed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description is written only in Chinese ("國際模型套餐,包含全球頂尖模型") with no indication that users may select another language or that the skill is intentionally limited to a Chinese-speaking locale. This creates a natural-language locale policy concern because it implicitly fixes presentation to one language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.