Back to skill

Security audit

Model Checker

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small, disclosed model-list lookup, with the main caveat that its HTTP dependencies should be updated before broad use.

Install only in an environment allowed to contact the listed company API endpoint. Before wider deployment, update axios and its transitive dependencies, regenerate the lockfile, and prefer exact reviewed versions. No credential use, local data access, persistence, or destructive behavior was found in the inspected artifact.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Known Vulnerable Dependency: axios==1.14.0 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
97% confidence
Finding

The lockfile pins axios 1.14.0, and the supplied advisories indicate multiple known issues including SSRF/proxy bypass and prototype-pollution-related request/credential compromise paths. For a skill whose purpose is to query internal available AI models, outbound HTTP requests are central to its function, so vulnerable HTTP client behavior materially increases risk to internal services, credentials, and response integrity.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
86% confidence
Finding

form-data 4.0.5 is reported vulnerable to CRLF injection through unescaped multipart field names/filenames. If this skill ever constructs multipart requests using user- or upstream-controlled metadata, an attacker may be able to smuggle malformed headers or manipulate downstream parsing, which is especially risky in internal service integrations.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.14.0 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
98% confidence
Finding

The package explicitly references axios 1.14.0, which the finding states is associated with multiple advisories including SSRF-related proxy bypass and other high-impact issues. Because this skill is intended to query internal company AI model availability, it likely performs internal HTTP requests, making flaws in the HTTP client more dangerous by increasing the risk of SSRF, credential leakage, request manipulation, or interception against internal services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill invokes an internal company API endpoint, but the markdown does not clearly disclose that using the skill will send a network request to that internal service. This can reduce user awareness and consent, and may cause unintentional disclosure of query metadata or internal service interaction, especially if the endpoint is only appropriate for internal users or environments.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The usage section suggests invoking the skill with natural-language phrases like '查询模型列表' and '显示可用的AI模型' without clarifying whether these are the only accepted triggers or providing exclusion conditions. This can create ambiguity about when the skill should activate versus when a general conversation about models should not invoke it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code makes an outbound HTTP request to an external service, but there is no confirmation prompt, user-facing notice, or explanatory comment indicating that network communication will occur. Because network calls can affect privacy or data flow, the lack of disclosure is relevant under the missing user warnings rule for code files.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: follow-redirects==1.15.11 — 1 advisory(ies): CVE-2026-40895 (follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Ta)

Low
Category
Supply Chain
Confidence
88% confidence
Finding

follow-redirects 1.15.11 is flagged for leaking custom authentication headers across cross-domain redirects. In an internal model-discovery skill, requests may carry API keys or internal auth headers; if redirects are followed to attacker-controlled domains, those secrets could be exposed and used to access internal resources.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The dependency is version-ranged with a caret (^1.14.0), which allows installation of newer 1.x releases without explicit review and can undermine reproducibility and supply-chain control. In a skill that queries internal available AI models, dependency behavior matters because network-facing libraries can affect how internal services are contacted, though this issue alone is primarily a hygiene and supply-chain hardening concern.

Content

Scanner excerpt · package.json (reported line 13)May include surrounding context.

json
"author": "",
  "license": "ISC",
  "dependencies": {
    "axios": "^1.14.0"
  }
}

Static analysis

No suspicious patterns detected.