Back to skill

Security audit

AI大模型专家|API中转与Token Hub企业网关

Security checks for vulnerabilities and agentic risk

Overview

This skill is a planning guide for authorized enterprise AI API gateways and token governance, with no executable code or hidden runtime behavior found.

Install this if you want structured guidance for designing an authorized AI API gateway or Token Hub. Users should still ensure the skill is invoked only for legitimate, authorized integrations and should not use it to route around provider terms, share third-party keys, or bypass quotas, regions, or billing rules.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger section matches on a long list of broad, common terms such as 'AI中转', 'API中转站', and vendor-name-plus-'中转', without clear exclusion criteria or disambiguation. This can cause the skill to activate in unrelated contexts and steer conversations toward gateway/token-hub guidance where it may be inapplicable, increasing the chance of unsafe or policy-sensitive assistance around proxying model access and credential handling.

Static analysis

No suspicious patterns detected.