Back to skill

Security audit

AI Model Watcher

Security checks for vulnerabilities and agentic risk

Overview

This skill fetches public OpenRouter model catalog data and stores it in a local SQLite database as documented.

Before installing, understand that running scan contacts OpenRouter and creates or updates a local SQLite catalog. Use --db if you want the database somewhere specific. I found no evidence of hidden execution, credential access, destructive actions, or unrelated persistence.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill documentation describes a scan command that fetches catalog data from external sources, which implies network access, but the skill declares no permissions or allowed-tools scope. Missing an explicit tool/network declaration weakens least-privilege controls and can allow the skill to run with broader capabilities than reviewers or execution frameworks expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The scan path fetches data from a remote API and later persists the returned model metadata into a local SQLite database, but the code provides no confirmation prompt and no explicit user-facing warning about the outbound network request or local data storage before execution. Although the CLI help hints at syncing a local database, there is no direct disclosure at the point of the safety-relevant operations themselves.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.