OrderOpenRouter - Buy from any API and signup with your claw and creditcard

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only OpenRouter integration skill whose main risks are expected: using a paid API key and sending prompts to external model providers.

Install this only if you want your agent to use OpenRouter. Use a dedicated revocable API key, set spending limits, review provider routing and privacy settings before sending confidential data, avoid :online for sensitive prompts unless web search data flow is acceptable, and enable ZDR or provider allowlists where needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill describes automatic provider routing, BYOK, and `:online` web search, all of which can cause user prompts, uploaded content, or results to be sent to third-party model providers or external search services. While the document mentions privacy controls and provider selection, it does not clearly warn that external transmission may occur by default, which creates a meaningful risk of unintended data disclosure for sensitive prompts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal