Back to skill

Security audit

Claude Code 接入第三方模型

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Claude Code model-switching tool, but it changes global agent configuration, handles API keys, routes prompts to third-party model providers, and can leave a local gateway running.

Install only if you intentionally want Claude Code traffic routed to third-party model providers and are comfortable with this skill modifying your user-level Claude settings. Use non-sensitive test prompts first, review any ~/.claude/profiles files for real API keys before switching, and stop/remove the local gateway and backups if you no longer need them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (33)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

先看账号可用清单:

bash
curl -s https://api.deepseek.com/models -H "Authorization: Bearer $KEY"

再拿候选名逐个打 Anthropic 兼容端点(这才是权威,/models 常漏别名):

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

先看账号可用清单:

bash
curl -s https://api.deepseek.com/models -H "Authorization: Bearer $KEY"

再拿候选名逐个打 Anthropic 兼容端点(这才是权威,/models 常漏别名):

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
99% confidence
Finding

This command extracts ANTHROPIC_AUTH_TOKEN directly from ~/.claude/settings.json into a shell variable for subsequent external requests. Even if the document advises not to print the key later, harvesting a credential from agent config materially increases the risk of leakage through logs, process inspection, shell history, or misuse by downstream commands.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

再拿候选名逐个打 Anthropic 兼容端点(这才是权威,/models 常漏别名):

bash
KEY=$(python -c "import json;print(json.load(open(r'C:/Users/<u>/.claude/settings.json'))['env']['ANTHROPIC_AUTH_TOKEN'])")
for M in "deepseek-flash" "deepseek-flash[1m]" "deepseek-v4-flash" "deepseek-chat" "deepseek-v4.1-flash"; do
  printf '%-24s => ' "$M"
  curl -s -m 45 https://api.deepseek.com/anthropic/v1/messages \

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Referencing ~/.claude/settings.json as the authoritative configuration path encourages modification and inspection of a sensitive agent config directory. In isolation the template is documentation, but in an agent skill this normalizes access to a location that commonly stores tokens and model routing settings.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

Step 3 · 配置模板

~/.claude/settings.json(用户级、跨项目,是唯一真相源):

json
{

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
95% confidence
Finding

The skill instructs reading project and user Claude configuration files, including .claude/settings.json, .claude/settings.local.json, and ~/.claude.json, which may contain API keys and other secrets. In a skill context, directing an agent to access these locations increases the chance of secret exposure beyond what is necessary for normal task completion.

Content

Scanner excerpt · SKILL.md (reported line 154)May include surrounding context.

except FileNotFoundError: pass "

2) 项目级覆盖(优先级高于用户级)

cat .claude/settings.json .claude/settings.local.json 2>/dev/null

3) ~/.claude.json 里的 model / env 字段

python -c "import json;d=json.load(open(r'C:/Users//.claude.json'));print({k:d[k] for k in ('model','env','primaryApiKey') if k in d})"

text

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

The backup instruction copies the full ~/.claude/settings.json, which likely contains API credentials, into another file location. Secret duplication increases exposure surface and retention time, making accidental disclosure or later compromise more likely.

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

md
## 收尾清单

- [ ] 改前备份:`cp ~/.claude/settings.json ~/.claude/backups/settings.json.bak-$(date +%Y%m%d-%H%M%S)`;
      若要动 HKCU,先把变量导出一份 json 到同目录。
- [ ] 改后**必须**跑 Step 5 验证主模型 + 子代理模型,不能只看配置文件。
- [ ] 报告里**不要回显 API Key**,只说前缀 + 长度。

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Declaring ~/.claude/settings.json as the single source of truth encourages placing all credentials and routing configuration into one agent-readable file. In a skill, that increases the blast radius if the file is later read, copied, or modified by other automation.

Content

Scanner excerpt · SKILL.md (reported line 388)May include surrounding context.

md
## Step 14 · 单一配置源(Single Source of Truth)

**结论:配置只写在 `~/.claude/settings.json`,不要同时在 Windows 环境变量里放一份。**

理由(实测):
1. **环境变量那份根本不起作用**。`settings.json` 的 `env` 块优先级更高(Step 5),

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
70% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · SKILL.md (reported line 429)May include surrounding context.

python
import os, subprocess, re
env = {k:v for k,v in os.environ.items()
       if not (k.upper().startswith("ANTHROPIC") or k.upper().startswith("CLAUDE_CODE"))}
p = subprocess.run([r"C:/Users/<u>/AppData/Roaming/npm/claude.cmd",
                    "-p", "hi", "--output-format", "json"],

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
92% confidence
Finding

The profile-switching design copies complete profile JSON files over ~/.claude/settings.json, potentially overwriting or proliferating embedded secrets and changing agent behavior silently. This creates both credential-handling risk and integrity risk for the agent's runtime configuration.

Content

Scanner excerpt · SKILL.md (reported line 751)May include surrounding context.

md
## 设计(可直接照搬到别的工具)

1. **profile 即模板**:`~/.claude/profiles/<name>.json` 存一份完整的 Claude Code
   `settings.json`;切换 = 复制覆盖 `~/.claude/settings.json`。
2. **切前必备份**:旧文件存 `~/.claude/backups/settings.json.bak-<时间戳>`;
   与目标内容相同则跳过(不刷屏)。
3. **是否需要网关由配置自身推出**,不靠额外元数据:

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/ccproxy.py (reported line 513)May include surrounding context.

python
oa_req = anthropic_to_openai(req)
        except Exception as e:
            self._send_error_anthropic(400, "invalid_request_error", "translate: %s" % e)
            return

        prompt_chars = sum(len(str(m.get("content", ""))) for m in oa_req["messages"])
        model_for_reply = req.get("model") or CONFIG["upstream"].get("model")

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

md
How it works:
    A profile is a JSON file in ~/.claude/profiles/<name>.json that fully
    describes Claude Code's settings.json for that upstream. Switching =
    copy profile -> ~/.claude/settings.json, then reconcile the gateway:

      * profile whose ANTHROPIC_BASE_URL points at 127.0.0.1:<gateway port>
        => local ccproxy gateway MUST be running -> start if down

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · scripts/ccswitch.py (reported line 16)May include surrounding context.

python
How it works:
    A profile is a JSON file in ~/.claude/profiles/<name>.json that fully
    describes Claude Code's settings.json for that upstream. Switching =
    copy profile -> ~/.claude/settings.json, then reconcile the gateway:

      * profile whose ANTHROPIC_BASE_URL points at 127.0.0.1:<gateway port>
        => local ccproxy gateway MUST be running -> start if down

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/ccswitch.py (reported line 219)May include surrounding context.

python
if not CCPROXY.exists():
        die("ccproxy.py not found: " + str(CCPROXY))
    GATEWAY_LOG.parent.mkdir(parents=True, exist_ok=True)
    env = os.environ.copy()
    for k in ("HTTP_PROXY", "HTTPS_PROXY", "http_proxy", "https_proxy",
              "ALL_PROXY", "all_proxy"):
        env.pop(k, None)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

L010 列出大量触发说法,其中“给 claude code 配置 deepseek/别的模型”“现在什么模型”等表述较泛,且未说明必须在何种上下文中才应激活该技能。文档也没有提供负例或排除条件来收窄触发范围,因此存在与普通对话重叠的风险。

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

Calling https://api.deepseek.com/ is an outbound network action to a third-party service. In this skill, that matters because the action is coupled with model validation and may involve protected credentials or prompt content being sent off-host.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

先看账号可用清单:

bash
curl -s https://api.deepseek.com/models -H "Authorization: Bearer $KEY"

再拿候选名逐个打 Anthropic 兼容端点(这才是权威,/models 常漏别名):

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

Calling https://api.deepseek.com/ is an outbound network action to a third-party service. In this skill, that matters because the action is coupled with model validation and may involve protected credentials or prompt content being sent off-host.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

先看账号可用清单:

bash
curl -s https://api.deepseek.com/models -H "Authorization: Bearer $KEY"

再拿候选名逐个打 Anthropic 兼容端点(这才是权威,/models 常漏别名):

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

This command sends a live request to a third-party endpoint using an API key harvested from local Claude settings. That combines secret access with outbound transmission, creating a clear path for credential misuse and possible data leakage to an untrusted remote service.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
KEY=$(python -c "import json;print(json.load(open(r'C:/Users/<u>/.claude/settings.json'))['env']['ANTHROPIC_AUTH_TOKEN'])")
for M in "deepseek-flash" "deepseek-flash[1m]" "deepseek-v4-flash" "deepseek-chat" "deepseek-v4.1-flash"; do
  printf '%-24s => ' "$M"
  curl -s -m 45 https://api.deepseek.com/anthropic/v1/messages \
    -H "x-api-key: $KEY" -H "anthropic-version: 2023-06-01" -H "content-type: application/json" \
    -d "{\"model\":\"$M\",\"max_tokens\":8,\"messages\":[{\"role\":\"user\",\"content\":\"hi\"}]}" \
    | python -c "import sys,json;d=json.load(sys.stdin);print('OK ->',d['model'] if 'model' in d else 'ERR '+str(d.get('error',{}).get('message'))[:160])"

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 223)May include surrounding context.

md
- 用同目录 `tag.txt` 给每一轮实验打标签,避免多次运行串味。
- `ANTHROPIC_BASE_URL` 支持 `http://`,指向 127.0.0.1 时记得把 `NO_PROXY` 加上 `127.0.0.1`。

**⚠️ 最大坑**:在 Bash 工具里用 `nohup ... &` 起的中继会**随该次命令的进程组一起被杀**,
表现为「Claude Code 连不上 → 一直重试 → 看起来像卡死」,
而且因为 SIGTERM 打断管道,**连报错都看不到**。
必须用工具自带的后台运行能力(`run_in_background`)启动长驻进程。

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 705)May include surrounding context.

md
- 用同目录 `tag.txt` 给每一轮实验打标签,避免多次运行串味。
- `ANTHROPIC_BASE_URL` 支持 `http://`,指向 127.0.0.1 时记得把 `NO_PROXY` 加上 `127.0.0.1`。

**⚠️ 最大坑**:在 Bash 工具里用 `nohup ... &` 起的中继会**随该次命令的进程组一起被杀**,
表现为「Claude Code 连不上 → 一直重试 → 看起来像卡死」,
而且因为 SIGTERM 打断管道,**连报错都看不到**。
必须用工具自带的后台运行能力(`run_in_background`)启动长驻进程。

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 469)May include surrounding context.

md
- Anthropic 协议 Base URL(Claude Code 用这个):`https://open.bigmodel.cn/api/anthropic`
  - ⚠️ 末尾**不要加 `/v1`**——Claude Code 会自动拼 `/v1/messages`,拼成
    `https://open.bigmodel.cn/api/anthropic/v1/messages`(这正是智谱的正确路径)。
  - 国际站 z.ai 同协议:`https://api.z.ai/api/anthropic`(Key 用 z.ai 平台发的)。
- API Key:`https://open.bigmodel.cn/usercenter/apikeys` 创建。
  填进 `ANTHROPIC_AUTH_TOKEN`(即 Key 本身,CC 会带 `x-api-key` 头,别加 `Bearer `)。
- 模型 ID(小写,OpenAI/Anthropic 端点通用):

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The skill recommends routing Claude Code traffic through third-party OpenAI-compatible endpoints, including anonymous/keyless providers. This can redirect sensitive prompts and tool outputs to services with unclear identity, retention, and access controls.

Content

Scanner excerpt · SKILL.md (reported line 533)May include surrounding context.

md
|---|---|---|---|
| **OpenCode Zen** | `https://opencode.ai/zen/v1/chat/completions` | `space-bunny-free` | **免 key(匿名)可用** |
| OpenRouter | `https://openrouter.ai/api/v1/chat/completions` | `stealth/space-bunny-alpha` | 需 key(注意:整段 `:free` 后缀会 404) |
| AI/ML API | `https://api.aimlapi.com/v1/chat/completions` | `stealth/space-bunny-alpha` | 需 key |

- **OpenCode Zen 免 key 实测(2026-09-29)**:不带任何 `Authorization` 头直接 POST
  `space-bunny-free` 即返回真实结果、`cost:"0"`。**账号被封也不用怕,直接换 Zen。**

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 603)May include surrounding context.

安装(装进 managed node workspace,别 npm install -g)

bash
mkdir -p "C:/Users/<u>/.workbuddy/binaries/node/workspace"
cd "C:/Users/<u>/.workbuddy/binaries/node/workspace"
"<node.exe>" "<版本根目录>/node_modules/npm/bin/npm-cli.js" install claude-code-router

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 797)May include surrounding context.

bash
python ccproxy.py --port 3457 --verbose                      # 前台带日志
python ccproxy.py --upstream <url> --model <name> --key <k>  # 临时换上游
curl -s http://127.0.0.1:3457/health                         # {"ok":true,"upstream":...}

CLI 参数优先于配置文件。当前上游:https://opencode.ai/zen/v1/chat/completions +

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
"$schema": "https://json.schemastore.org/claude-code-settings.json",
  "env": {
    "ANTHROPIC_AUTH_TOKEN": "sk-YOUR-DEEPSEEK-KEY-HERE",
    "ANTHROPIC_BASE_URL": "https://api.deepseek.com/anthropic",
    "ANTHROPIC_DEFAULT_FABLE_MODEL": "deepseek-flash[1m]",
    "ANTHROPIC_DEFAULT_FABLE_MODEL_NAME": "deepseek-flash",
    "ANTHROPIC_DEFAULT_HAIKU_MODEL": "deepseek-flash",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · examples/profiles/deepseek.json (reported line 5)May include surrounding context.

json
"$schema": "https://json.schemastore.org/claude-code-settings.json",
  "env": {
    "ANTHROPIC_AUTH_TOKEN": "sk-YOUR-DEEPSEEK-KEY-HERE",
    "ANTHROPIC_BASE_URL": "https://api.deepseek.com/anthropic",
    "ANTHROPIC_DEFAULT_FABLE_MODEL": "deepseek-flash[1m]",
    "ANTHROPIC_DEFAULT_FABLE_MODEL_NAME": "deepseek-flash",
    "ANTHROPIC_DEFAULT_HAIKU_MODEL": "deepseek-flash",

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
examples/profiles/spacebunny.json:5