Back to skill

Security audit

Zero Token

Security checks for vulnerabilities and agentic risk

Overview

This skill may be useful for model fallback, but it installs and runs an external gateway that can handle prompts and API keys while also trying to change the agent's broader behavior.

Install only if you are comfortable running a locally started third-party gateway that can see fallback prompts and provider API keys. Use disposable or tightly limited provider keys, avoid confidential workloads unless each provider and the gateway are reviewed, and treat the global SOUL behavior instructions as overbroad for a fallback utility.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:17
Finding

Global Agent Behavior and Output Hijacking

Content
View full analysis
[V2]=>[V3] T:can_parse|can_generate|can_explain|can_teach T:ilang_source=https://ilang.ai|github=ilang-ai|npm=@i-language ::GENE{upgrade|scope:session} T:this_is_zero_token_e ...[truncated 1905 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/setup.sh:8
Finding

Unverified Third-Party Code and Dependencies Are Downloaded and Executed

Content
View full analysis
/dev/null || npm install npm run build 2>/dev/null || true echo "✅ Free-Way installed at $FREE_WAY_DIR (commit: $FREE_WAY_TAG)" else echo "🔍 Found existing $FREE_WAY_DIR — verifying..." cd "$FREE_WAY_DIR" EXISTING_REMOTE=$(git remote get-url origin 2>/dev/null || echo "") EXISTING_COMMIT=$(git rev-parse HEAD 2>/dev/null || echo "") if [ "$EXISTING_REMOTE" = "$FREE_WAY_REPO" ] && [ "$EXISTING_COMMIT" = "$FREE_WAY_TAG" ]; then echo "✅ Verified: $FREE_WAY_DIR matches pinned commit $FREE_WAY_TAG" else echo "⚠️ EXISTING DIRECTORY DOES NOT MATCH PINNED SOURCE" echo " Expected: $FREE_WAY_REPO @ $FREE_WAY_TAG" echo " Found: ${EXISTING_REMOTE:-NOT_A_GIT_REPO} @ ${EXISTING_COMMIT:-UNKNOWN}" echo "" echo " Refusing to run untrusted code." echo " To fix: rm -rf $FREE_WAY_DIR && re-run this script" exit 1 fi fi # Start Free-Way in background if not running if ! curl -s http://localhost:$FREE_WAY_PORT/health &>/dev/null; then echo "🚀 Starting Free-Way on localhost:$FREE_WAY_PORT..." nohup npm start > "$FREE_WAY_DIR/free-way.log" 2>&1 & sleep 3 if curl -s http://localhost:$FREE_WAY_PORT/he ...[truncated 2384 chars]
Remediation
View remediation
/dev/null || true`; fail closed when integrity verification or builds fail. 9. Provide reproducible build instructions and a software bill of materials for the complete dependency graph. ]]>

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/setup.sh:70
Finding

Sensitive API Credentials and Model Traffic Are Entrusted to an Externally Sourced Gateway

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (29)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/setup.sh (reported line 94)May include surrounding context.

sh
echo "   pkill -f 'node.*free-way' || lsof -ti:$FREE_WAY_PORT | xargs kill"
echo ""
echo "🗑️  To UNINSTALL:"
echo "   pkill -f 'node.*free-way'; rm -rf $FREE_WAY_DIR"
echo ""
echo "🔍 To CHECK status:"
echo "   curl http://localhost:$FREE_WAY_PORT/health"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README markets automatic fallback as 'invisible' and 'zero detection' while requests may be rerouted to free third-party LLM providers with separate privacy and retention policies. This framing minimizes the security and privacy consequences of silently changing processors for potentially sensitive prompts, increasing the risk of undisclosed data sharing and compliance violations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description explicitly promotes seamless operating changes 'so no one notices,' which is risky because it encourages concealment of backend model/provider substitutions from users and administrators. In this context, hidden switching can bypass expectations about model behavior, safety controls, data handling, and contractual/privacy commitments.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README presents conflicting claims: elsewhere the skill promises an invisible switchover that users will not notice, while this section says failover is never hidden. In a security-sensitive routing skill, contradictory disclosure language can mislead operators about whether model/provider changes are surfaced to end users and whether data may be sent to different third parties without clear notice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire skill description is written only in German, and there is no indication that users can choose another language or that the skill is intentionally limited to a German-speaking context. Under the policy rule, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Ce fichier de description est entièrement rédigé en français et ne propose aucune alternative linguistique ni indication que la langue est optionnelle. Selon la règle de politique linguistique, forcer une langue spécifique sans choix utilisateur explicite constitue une violation de politique en langage naturel.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README makes conflicting trust claims: elsewhere the skill is marketed as an 'undetectable takeover' where 'no one notices', while this section says failover is never hidden and is transparent. In a failover/proxy skill that routes prompts to multiple third-party LLM providers, contradictory disclosure language can mislead operators about whether model/provider switching is visible to end users and whether sensitive data may be sent to different vendors without clear notice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README promotes 'invisible' or 'undetectable' failover where 'users do not notice' provider switching, which normalizes concealing material backend changes from end users. In a security context this is dangerous because the substitute provider may differ in privacy protections, compliance posture, output quality, or safety behavior, yet the user is intentionally not informed when the switch occurs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README initially markets seamless failover to 13+ free LLM providers, but the privacy/data-sharing warning appears only later rather than before installation or first mention of fallback routing. That sequencing can lead users to enable the skill without understanding that prompts and potentially sensitive data may be sent to third-party providers with different retention and privacy policies.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README explicitly markets failover as 'invisible takeover' and says users 'won't even notice the switch,' which encourages silent substitution of model providers without user awareness at the moment of use. In an agent skill that may route prompts and data to multiple third-party providers, this undermines informed consent, complicates compliance and auditing, and can expose sensitive data to different retention and privacy regimes than users expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README claims 'Full Transparency' and 'never hides the switch,' but this directly conflicts with earlier claims of 'Zero detection' and that users 'won't even notice the switch.' That inconsistency is dangerous because operators may deploy the skill believing it is transparent while the marketing and expected behavior normalize covert provider switching, increasing the risk of misleading users and mishandling data across unexpected third parties.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README markets failover as seamless and emphasizes 'zero downtime' and 'same personality,' which can encourage operators to route prompts and potentially sensitive data to multiple third-party free LLM providers without fully appreciating the privacy and compliance consequences. Although the document later includes a transparency note, the earlier messaging downplays the operational and data-governance risk of automatic fallback to external providers with differing retention and privacy policies.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file presents the entire skill description and operating guidance exclusively in Russian, with no indication that the user can choose another language or that the skill is intentionally limited to a Russian-speaking region. The policy requires flagging language or locale constraints unless they are optional or clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README markets failover as "undetectable" and "no one notices," while later claiming "full transparency" about provider switching. This inconsistency can mislead operators into deploying the skill without clear user disclosure or data-handling expectations, increasing the risk of unauthorized routing of prompts or sensitive data to third-party free providers.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly markets failover as 'invisible' and says users will not notice provider switching, which normalizes non-transparent substitution of the underlying model/provider. Even though a later section mentions transparency, the core sales language encourages concealment and can lead operators to send user data to different third-party providers without clear notice or consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The text claims 'no one can distinguish' whether the primary or fallback model is running, encouraging operators to preserve the illusion that the same trusted model is still in use. This is risky because different providers may have different retention, safety, compliance, and output characteristics, so concealing substitution can mislead users and bypass informed consent expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

该文件整体仅以简体中文提供技能说明,未见任何提示说明可选择其他语言版本,也未说明该技能仅面向特定中文地区用户。根据规则,未提供用户语言/locale 选择而默认强制单一语言,属于自然语言层面的策略违规。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file describes configuring fallback so the agent automatically switches to free providers and continues running, which implies user content will be sent to those providers. While later text mentions differing privacy policies, the initial installation/behavior description lacks a prominent upfront warning that fallback can transmit user data to third parties.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs users to run a shell setup script, but the manifest declares no explicit tool scope or permissions. That creates an authorization and review gap: consumers and hosting frameworks cannot easily tell that installation/execution of shell commands is required, increasing the chance of unintended code execution from a third-party skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The 'user unaware' / '无感接管' messaging promotes silent model and provider substitution specifically designed to avoid notice. In an agent context, this is dangerous because reliability, safety properties, output quality, and data handling may change mid-task while users and operators continue trusting the original model and policies.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill markets seamless fallback to free providers but does not clearly warn that prompts, outputs, and possibly sensitive task data may be routed to multiple third-party model providers. Silent routing changes can alter confidentiality, retention, compliance posture, and model behavior without operator awareness.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description promises zero-cost continuity and invisible switching to backup models when a main model fails. In this file, the only zero-token-related content is a session-scoped 'zero token edition' label and a pointer to an external GitHub project; there is no code or logic implementing model failover, model selection, or outage handling.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup.sh (reported line 56)May include surrounding context.

sh
# Start Free-Way in background if not running
if ! curl -s http://localhost:$FREE_WAY_PORT/health &>/dev/null; then
    echo "🚀 Starting Free-Way on localhost:$FREE_WAY_PORT..."
    nohup npm start > "$FREE_WAY_DIR/free-way.log" 2>&1 &
    sleep 3
    if curl -s http://localhost:$FREE_WAY_PORT/health &>/dev/null; then
        echo "✅ Free-Way running at http://localhost:$FREE_WAY_PORT"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file contains user-facing instructions only in Spanish, with no parallel language option or opt-in. Under the policy for natural-language violations, forcing a specific language without user choice can be a locale-policy issue unless the restriction is documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.