Back to skill

Security audit

中国AI API统一网关

Security checks for vulnerabilities and agentic risk

Overview

The skill is a legitimate AI API gateway guide, but the included gateway can expose the operator's provider API access to anyone who can reach it if run as shipped.

Review carefully before installing. Do not expose the gateway to a network without adding authentication, binding to localhost or a protected interface, rate limiting requests, and controlling fallback. Store provider keys in environment variables or a secret manager rather than committed YAML files, and avoid sending confidential prompts or source code to third-party providers unless approved.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/gateway.py:54
Finding

Unauthenticated AI gateway listens on all network interfaces

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/gateway.py:21
Finding

Provider API credentials are expected in plaintext YAML configuration

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (40)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill includes concrete network-call examples and references to reading local references/docs, but it does not declare an explicit tool scope such as allowed network destinations or file access boundaries. In an agent setting, this can cause overbroad runtime permissions and make unintended external access harder to audit or constrain.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill content is entirely in Chinese and is framed as a China-specific API gateway workflow, but it does not explicitly state that the locale/language restriction is intentional or give users a language choice. Under the policy, forcing a specific language without opt-in is a natural-language policy concern unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs users to send prompts and API keys to third-party AI services but does not clearly warn that user content and metadata will leave the local environment. This omission can lead users to disclose sensitive prompts, personal data, or proprietary material without informed consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

The referenced endpoint is an external destination that will receive submitted prompt data when users follow the example. Because the skill markets easy switching and free usage, users may be nudged to transmit data without evaluating the provider's trust or compliance posture.

Content

Scanner excerpt · SKILL.md (reported line 158)May include surrounding context.

bash
# 小米MiMo
curl https://api.xiaomimimo.com/v1/chat/completions \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $MIMO_API_KEY" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

The referenced endpoint is an external destination that will receive submitted prompt data when users follow the example. Because the skill markets easy switching and free usage, users may be nudged to transmit data without evaluating the provider's trust or compliance posture.

Content

Scanner excerpt · SKILL.md (reported line 158)May include surrounding context.

bash
# 小米MiMo
curl https://api.xiaomimimo.com/v1/chat/completions \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $MIMO_API_KEY" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

This example sends user content and authorization data to an external DeepSeek endpoint. The risk is contextual rather than malicious: the skill encourages third-party transmission but does not pair it with adequate user warning or data-minimization guidance.

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

md
}'

# DeepSeek
curl https://api.deepseek.com/v1/chat/completions \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $DEEPSEEK_API_KEY" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

The Python SDK example configures a client to send data to an external AI provider, which can expose prompt content and usage metadata outside the user's environment. The danger is amplified by the absence of nearby privacy warnings and operational safeguards.

Content

Scanner excerpt · SKILL.md (reported line 194)May include surrounding context.

md
# 小米MiMo
client = OpenAI(
    base_url="https://api.xiaomimimo.com/v1",
    api_key="sk-xxxxx"
)

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

This SDK configuration points to an external provider and will transmit prompts and credentials during use. That is expected for API integration, but still a genuine privacy/security risk if users are not clearly informed and if sensitive data is routed by default.

Content

Scanner excerpt · SKILL.md (reported line 200)May include surrounding context.

md
# DeepSeek
client = OpenAI(
    base_url="https://api.deepseek.com/v1",
    api_key="sk-xxxxx"
)

External Transmission

Medium
Category
Data Exfiltration
Confidence
79% confidence
Finding

The streaming example continuously sends and receives data from an external provider, which can leak user content in real time to third-party infrastructure. Streaming does not reduce the disclosure risk and may complicate auditability if not documented.

Content

Scanner excerpt · SKILL.md (reported line 228)May include surrounding context.

md
from openai import OpenAI

client = OpenAI(
    base_url="https://api.xiaomimimo.com/v1",
    api_key="sk-xxxxx"
)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The multi-provider gateway/failover examples omit that the same user request may be routed or retried across multiple vendors, potentially duplicating disclosure of prompts and embedded data. In a gateway context, this increases exposure because one logical request can be propagated to more than one external service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The gateway configuration explicitly defines third-party provider endpoints and API keys, enabling outbound transmission of user content beyond the local system. In a routing configuration, this represents a real exposure surface that should be clearly bounded and disclosed.

Content

Scanner excerpt · SKILL.md (reported line 251)May include surrounding context.

md
# gateway.yaml
providers:
  - name: mimo
    base_url: https://api.xiaomimimo.com/v1
    api_key: ${MIMO_API_KEY}
    models: [mimo-v2.5]
    priority: 1

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

This provider entry adds another external destination for routed prompts and can increase disclosure surface when fallback is enabled. The gateway context makes the risk more significant because multiple configured endpoints may receive equivalent or overlapping user data.

Content

Scanner excerpt · SKILL.md (reported line 257)May include surrounding context.

md
priority: 1
    
  - name: deepseek
    base_url: https://api.deepseek.com/v1
    api_key: ${DEEPSEEK_API_KEY}
    models: [deepseek-chat]
    priority: 2

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The code hardcodes an external provider base URL in a multi-provider routing function, enabling outbound transmission of prompts to that service. Because the code is framed as simple failover, users may underestimate that confidential content may leave their environment.

Content

Scanner excerpt · SKILL.md (reported line 277)May include surrounding context.

md
PROVIDERS = {
    "mimo": {
        "base_url": "https://api.xiaomimimo.com/v1",
        "api_key": os.getenv("MIMO_API_KEY"),
        "models": ["mimo-v2.5"]
    },

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

This additional provider in the failover code increases the number of external parties that may receive the same message. In the context of automatic retries, the same prompt could be disclosed to multiple services without an explicit user decision.

Content

Scanner excerpt · SKILL.md (reported line 282)May include surrounding context.

md
"models": ["mimo-v2.5"]
    },
    "deepseek": {
        "base_url": "https://api.deepseek.com/v1",
        "api_key": os.getenv("DEEPSEEK_API_KEY"),
        "models": ["deepseek-chat"]
    }

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

L288-L292 的 chat(message, prefer="mimo") 带有“简单负载均衡”说明,并通过 [prefer] + list(PROVIDERS.keys()) 看起来要优先使用首选 provider;但代码在循环首项 provider_name == prefer 时立即 continue,导致首选 provider 永远不会被尝试。这不是单纯实现细节遗漏,而是注释/接口意图与实际行为直接相反,会误导使用者对路由与故障切换逻辑的理解。

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
79% confidence
Finding

The sample code configures a client for a third-party endpoint and will transmit prompts and authentication material during operation. In a code-generation use case, users may send proprietary source code, making the disclosure risk contextually more sensitive than generic chat.

Content

Scanner excerpt · SKILL.md (reported line 389)May include surrounding context.

md
from openai import OpenAI

client = OpenAI(
    base_url="https://api.deepseek.com/v1",
    api_key="sk-xxxxx"
)

Rp1

Medium
Category
MCP Rug Pull
Confidence
78% confidence
Finding

The Docker deployment example uses an unpinned image reference, which can resolve to different content over time or be replaced upstream. Users following the example may pull a malicious or incompatible image without noticing, creating a supply-chain risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file presents all instructions, examples, and parameter descriptions exclusively in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/details.md (reported line 38)May include surrounding context.

bash
# 基础对话(curl)
curl http://localhost:18080/v1/chat/completions \
  -H "Content-Type: application/json" \
  -d '{
    "model": "auto",

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and the rest of the document present all instructions in Chinese only, which can constitute a language/locale policy violation when no user opt-in or alternative language option is provided. The content does not state that it is intentionally limited to a Chinese-speaking or China-specific audience as a justified constraint.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/platforms.md (reported line 205)May include surrounding context.

平台信息

text
官网:https://platform.lingyiwanwu.com
API地址:https://api.lingyiwanwu.com/v1
模型:
  - yi-lightning:快速模型(免费额度)
  - yi-large:更强模型

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/platforms.md (reported line 227)May include surrounding context.

平台信息

text
官网:https://www.sensenova.cn
API地址:https://api.sensenova.cn/v1
模型:DeepSeek V4 Flash / SenseNova 6.7 Flash-Lite / SenseNova U1 Fast
额度:每5小时刷新(DS-V4-Flash 500次, SN-6.7 1500次, SN-U1 1500次)
上下文:256K

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/platforms.md (reported line 246)May include surrounding context.

平台信息

text
官网:https://www.sensenova.cn
API地址:https://api.sensenova.cn/v1
模型:DeepSeek V4 Flash / SenseNova 6.7 Flash-Lite / SenseNova U1 Fast
额度:每5小时刷新(DS-V4-Flash 500次, SN-6.7 1500次, SN-U1 1500次)
上下文:256K

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/platforms.md (reported line 266)May include surrounding context.

平台信息

text
官网:https://cloud.siliconflow.cn
API地址:https://api.siliconflow.cn/v1
特点:聚合多模型平台
免费模型:Qwen/Llama/GLM等部分模型

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/platforms.md (reported line 282)May include surrounding context.

平台信息

text
官网:https://cloud.siliconflow.cn
API地址:https://api.siliconflow.cn/v1
特点:聚合多模型平台
免费模型:Qwen/Llama/GLM等部分模型

Static analysis

No suspicious patterns detected.