Back to skill

Security audit

Model Router

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it needs review because its public instructions promise real multi-model routing while the included code only simulates model calls and the install command is unpinned.

Review before installing. Treat this as a demo or incomplete implementation unless the publisher clarifies that it is intentionally simulated. If a future version performs real routing, assume prompts may be sent to several external LLM providers and avoid secrets, regulated data, or private code unless you have approved those providers. Prefer a pinned, verified install path and avoid running the npx install command with elevated privileges.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:106
Finding

Unpinned Third-Party Package Execution During Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 106
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable code:

bash
npx clawhub install model-router-waai

Technical Analysis

The documented installation command invokes clawhub through npx without specifying an exact package version or integrity value. If the package is not already available locally, npx can retrieve it from the configured npm registry and execute it immediately.

Consequently, the code executed by this command is not immutable relative to the reviewed project. A future package release, package ownership transfer, registry compromise, or maintainer account compromise could alter installation behavior after this audit. The command also provides no lockfile, checksum, signature verification, or explicit trusted-registry constraint.

No evidence was found that the current project itself contains a malicious payload. The risk arises from the mutable external dependency execution path prescribed by its installation documentation.

Attack Path

  1. An attacker compromises the publisher account, registry entry, or distribution process for the unpinned clawhub package.
  2. The attacker publishes a modified package version containing malicious lifecycle or CLI code.
  3. A user follows the installation command in SKILL.md.
  4. npx resolves and downloads the attacker-controlled version because no exact version is pinned.
  5. npx executes the package with the permissions of the installing user.
  6. The malicious package can access resources available to that user and perform arbitrary actions within that security context.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the installing user's privileges. Depending on that user's permissions and environment, the affected scope may include user-owned files, accessible credentials, development configuration ...[truncated 192 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin clawhub to an exact, reviewed version rather than allowing npx to resolve the latest available release.
  • Document and enforce the expected official package registry and package publisher.
  • Verify package provenance and integrity through registry signatures, checksums, or an equivalent trusted verification mechanism.
  • Use a lockfile where the installation workflow permits it, and review dependency changes before updating the pinned version.
  • Prefer installing and auditing the required CLI separately instead of combining remote retrieval and immediate execution.
  • Avoid running the installation command with administrative or otherwise elevated privileges.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This skill routes user tasks to multiple third-party LLM providers in parallel, but the description does not clearly warn that prompts and possibly sensitive data will be transmitted externally to several providers. In context, this is more dangerous than a normal single-model skill because it multiplies data exposure across multiple organizations and jurisdictions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The installation command uses npx clawhub install model-router-waai without pinning a specific package version. This can cause users to install whatever version is current at execution time, increasing supply-chain risk if a malicious or compromised release is published later.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · model_router.py (reported line 24)May include surrounding context.

python
# 模型端点映射
LLM_ENDPOINTS = {
    "gpt4": {"url": "https://api.openai.com/v1/chat/completions", "model": "gpt-4"},
    "claude": {"url": "https://api.anthropic.com/v1/messages", "model": "claude-3-opus"},
    "kimi": {"url": "https://api.moonshot.cn/v1/chat/completions", "model": "kimi-k2"},
    "deepseek": {"url": "https://api.deepseek.com/v1/chat/completions", "model": "deepseek-chat"},

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · model_router.py (reported line 25)May include surrounding context.

python
# 模型端点映射
LLM_ENDPOINTS = {
    "gpt4": {"url": "https://api.openai.com/v1/chat/completions", "model": "gpt-4"},
    "claude": {"url": "https://api.anthropic.com/v1/messages", "model": "claude-3-opus"},
    "kimi": {"url": "https://api.moonshot.cn/v1/chat/completions", "model": "kimi-k2"},
    "deepseek": {"url": "https://api.deepseek.com/v1/chat/completions", "model": "deepseek-chat"},
    "qwen": {"url": "https://dashscope.aliyuncs.com/compatible-mode/v1/chat/completions", "model": "qwen-plus"},

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · model_router.py (reported line 26)May include surrounding context.

python
LLM_ENDPOINTS = {
    "gpt4": {"url": "https://api.openai.com/v1/chat/completions", "model": "gpt-4"},
    "claude": {"url": "https://api.anthropic.com/v1/messages", "model": "claude-3-opus"},
    "kimi": {"url": "https://api.moonshot.cn/v1/chat/completions", "model": "kimi-k2"},
    "deepseek": {"url": "https://api.deepseek.com/v1/chat/completions", "model": "deepseek-chat"},
    "qwen": {"url": "https://dashscope.aliyuncs.com/compatible-mode/v1/chat/completions", "model": "qwen-plus"},
    "ernie": {"url": "https://qianfan.baidubce.com/v3/chat/ernie-4.0-8k", "model": "ernie-4.0-8k"},

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · model_router.py (reported line 27)May include surrounding context.

python
"gpt4": {"url": "https://api.openai.com/v1/chat/completions", "model": "gpt-4"},
    "claude": {"url": "https://api.anthropic.com/v1/messages", "model": "claude-3-opus"},
    "kimi": {"url": "https://api.moonshot.cn/v1/chat/completions", "model": "kimi-k2"},
    "deepseek": {"url": "https://api.deepseek.com/v1/chat/completions", "model": "deepseek-chat"},
    "qwen": {"url": "https://dashscope.aliyuncs.com/compatible-mode/v1/chat/completions", "model": "qwen-plus"},
    "ernie": {"url": "https://qianfan.baidubce.com/v3/chat/ernie-4.0-8k", "model": "ernie-4.0-8k"},
    "gemini": {"url": "https://generativelanguage.googleapis.com/v1/models/gemini-pro:generateContent", "model": "gemini-pro"},

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The _call_api method is documented as an 'actual API call' and the module defines real provider endpoints, but the implementation merely sleeps and returns a fabricated string. This is not just incomplete documentation: it actively misrepresents the runtime behavior of the skill as performing multi-LLM invocation when it does not contact any model service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The usage examples are written entirely around Chinese-language tasks and merge prompts, while the skill markets itself generally rather than as a China-specific or Chinese-only tool. This can be read as imposing a specific language/locale by default without documenting user choice or a justified locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The module docstring and later CLI output mix Chinese and English, which imposes a locale assumption in user-facing text. Under the policy, language constraints should either be optional or explicitly justified; this file does not provide a language-selection mechanism or explain why bilingual Chinese output is required.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.