Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- scripts/free-models.js:13
Security audit
Security checks across malware telemetry and agentic risk
This skill is a simple OpenRouter model-listing helper, with the main caveat that it asks for an API key even though the reviewed request does not use it.
Reasonable to install for discovering free or low-cost OpenRouter models. If you run the CLI, use a revocable OpenRouter key and be aware the current code appears to require that key even though it only fetches the public model list.
65/65 vendors flagged this skill as clean.
Detected: suspicious.env_credential_access