Back to skill

Security audit

Chinese LLM Router

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a legitimate LLM router, but it stores API keys insecurely and can send prompts and credentials to configurable external endpoints without strong safeguards.

Review before installing. Use only with prompts you are comfortable sending to the selected LLM providers, avoid regulated or confidential data unless approved, restrict config file permissions manually, and do not configure non-HTTPS or untrusted base URLs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup.js:158
Finding

API Credentials Stored Without Restrictive File Permissions

Content
View full analysis

Vulnerability Details

File Location: scripts/setup.js, lines 158–159
Vulnerability Type: API credential exposure through insecure file permissions
Risk Level: Medium

Vulnerable Code

js
if (!fs.existsSync(CONFIG_DIR)) fs.mkdirSync(CONFIG_DIR, { recursive: true });
fs.writeFileSync(CONFIG_FILE, JSON.stringify(config, null, 2));

Technical Analysis

The setup script stores provider API keys in ~/.chinese-llm-router/config.json. It does not specify restrictive permissions when creating either the configuration directory or the file.

Consequently, the effective permissions depend on the process umask. In an environment with a permissive umask, the configuration may be readable by other local users. If the file already exists with unsafe permissions, the script also does not correct those permissions when overwriting it.

The stored configuration contains bearer credentials that authorize requests to paid external LLM services. Although no deliberate credential exfiltration was identified, insecure local storage can disclose those credentials to another local principal.

Attack Path

  1. A user runs node scripts/setup.js.
  2. The user enters one or more provider API keys.
  3. The script writes the keys to ~/.chinese-llm-router/config.json without setting an explicit file mode.
  4. A permissive umask or pre-existing unsafe permissions leave the file readable by another local user or process.
  5. The attacker reads the configuration and extracts the provider API keys.
  6. The attacker uses the credentials to make authorized requests against the affected provider accounts.

Impact Assessment

Exploitation requires local filesystem access and permissions sufficient to read the configuration file. A successful attacker may obtain the same provider API authorization represented by the stolen keys, potentially allowing:

  • Unauthorized consumption of paid API quotas or credits.
  • Acces ...[truncated 261 chars]
Remediation
View remediation

Remediation Suggestions

  • Create the configuration directory with mode 0700.
  • Create and maintain the configuration file with mode 0600.
  • Correct permissions on existing directories and files before reading or updating them.
  • Write updates atomically through a securely created temporary file in the same directory.
  • Reject symbolic links and verify that the destination is a regular file owned by the current user.
  • Prefer an operating-system credential manager or secret store instead of plaintext JSON when available.

Example hardening:

js
fs.mkdirSync(CONFIG_DIR, { recursive: true, mode: 0o700 });
fs.chmodSync(CONFIG_DIR, 0o700);

fs.writeFileSync(CONFIG_FILE, JSON.stringify(config, null, 2), {
  mode: 0o600,
  flag: 'w'
});
fs.chmodSync(CONFIG_FILE, 0o600);

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/router.js:112
Finding

Plaintext HTTP Endpoints Can Expose API Keys and Conversation Data

Content
View full analysis

Vulnerability Details

File Location: scripts/router.js, lines 112–127
Vulnerability Type: Transmission of credentials and sensitive data over an unencrypted protocol
Risk Level: Medium

Vulnerable Code

js
const url = new URL(provider.baseUrl + '/chat/completions');
const isHttps = url.protocol === 'https:';
const client = isHttps ? https : http;

const body = JSON.stringify({
  model,
  messages,
  temperature: options.temperature ?? 0.7,
  max_tokens: options.max_tokens ?? 4096,
  stream: options.stream ?? false,
  ...options.extra
});

const req = client.request({
  hostname: url.hostname,
  port: url.port || (isHttps ? 443 : 80),
  path: url.pathname + '/chat/completions',
  method: 'POST',
  headers: {
    'Content-Type': 'application/json',
    'Authorization': `Bearer ${provider.apiKey}`,

Technical Analysis

The router obtains provider.baseUrl from the local configuration and supports both HTTPS and plaintext HTTP endpoints. It does not enforce TLS, restrict the protocol, or validate the destination against known provider hostnames.

When an HTTP URL is configured, the router sends the provider bearer token and complete message body without transport encryption. Anyone capable of observing or modifying the relevant network traffic can recover the credential and conversation content.

Because the destination comes from editable configuration, malicious or unauthorized configuration modification can also redirect future prompts and credentials to an attacker-controlled endpoint. HTTPS enforcement would protect network confidentiality, while destination validation would additionally reduce redirection risks.

Attack Path

  1. A provider entry in ~/.chinese-llm-router/config.json is configured or altered to use an http: base URL.
  2. The user or an integrating application invokes route() for a model associated with that provider.
  3. `chatCompletion() ...[truncated 986 chars]
Remediation
View remediation

Remediation Suggestions

  • Reject all protocols other than https: before constructing the request.
  • Maintain an allowlist of expected provider hostnames and reject unexpected destinations.
  • If local development endpoints are required, permit plaintext HTTP only for explicit loopback addresses through a separate, disabled-by-default option.
  • Validate the complete provider configuration before transmitting credentials.
  • Avoid following redirects to untrusted origins, especially redirects that could retain authorization headers.
  • Document clearly that prompts are transmitted to third-party providers.

Example protocol enforcement:

js
const url = new URL(provider.baseUrl);

if (url.protocol !== 'https:') {
  throw new Error('Provider endpoints must use HTTPS');
}

const allowedHosts = new Set([
  'api.deepseek.com',
  'dashscope.aliyuncs.com',
  'open.bigmodel.cn',
  'api.moonshot.cn'
]);

if (!allowedHosts.has(url.hostname)) {
  throw new Error(`Unapproved provider hostname: ${url.hostname}`);
}
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (29)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 122)May include surrounding context.

md
## Setup

1. Get API keys from the providers you want (most offer free tiers):
   - DeepSeek: https://platform.deepseek.com
   - Qwen (Alibaba): https://dashscope.console.aliyun.com
   - GLM (Zhipu): https://open.bigmodel.cn

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

md
node scripts/setup.js

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises seamless routing to multiple Chinese LLM providers but does not warn users that their prompts and conversation content may be transmitted to third-party services. This creates a real transparency and privacy risk because users may unknowingly send sensitive data to external providers, potentially across jurisdictions with different data handling practices.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The documented DeepSeek API endpoint indicates that user prompts and potentially conversation history will be transmitted to an external third-party service. In this skill's context, external transmission is the core function, so the issue is not the endpoint itself but the lack of clear disclosure, consent, and data-minimization guidance.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
"providers": {
    "deepseek": {
      "apiKey": "sk-xxx",
      "baseUrl": "https://api.deepseek.com/v1",
      "models": ["deepseek-chat", "deepseek-reasoner"]
    },
    "qwen": {

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The Moonshot/Kimi API endpoint represents third-party data transmission of prompts or chat context. Because the skill encourages easy switching and testing across providers, users may send sensitive data externally without understanding the privacy consequences.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
},
    "kimi": {
      "apiKey": "sk-xxx",
      "baseUrl": "https://api.moonshot.cn/v1",
      "models": ["kimi-k2.5", "kimi-k2.5-thinking"]
    },
    "doubao": {

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The MiniMax API endpoint shows that conversation content can be forwarded to an external provider. This becomes risky when combined with the marketing language of 'no config headaches,' which downplays the operational and privacy implications of sending data off-platform.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
},
    "minimax": {
      "apiKey": "xxx",
      "baseUrl": "https://api.minimax.chat/v1",
      "models": ["minimax-m2.5"]
    },
    "step": {

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The StepFun endpoint is another external transmission path for user content. The danger is contextual: the skill is built to route conversations, but it does not pair that behavior with adequate privacy warnings, jurisdictional notice, or secure-use guidance.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

md
},
    "step": {
      "apiKey": "xxx",
      "baseUrl": "https://api.stepfun.com/v1",
      "models": ["step-3.5-flash"]
    },
    "baichuan": {

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The Baichuan API endpoint enables transmission of prompts and possibly retained context to a third party. The risk is amplified by features like auto-fallback and batch compare, which may replicate the same sensitive prompt across multiple providers.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
},
    "baichuan": {
      "apiKey": "xxx",
      "baseUrl": "https://api.baichuan-ai.com/v1",
      "models": ["baichuan4-turbo"]
    },
    "spark": {

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The Hunyuan endpoint is an external data egress point for prompt and conversation data. In a router skill that can automatically select providers, this creates meaningful privacy and compliance risk if users are not informed where their data is going.

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

md
},
    "hunyuan": {
      "apiKey": "xxx",
      "baseUrl": "https://api.hunyuan.cloud.tencent.com/v1",
      "models": ["hunyuan-turbo-s"]
    }
  },

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 89)May include surrounding context.

All providers accept:

bash
curl -X POST <baseUrl>/chat/completions \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer <apiKey>" \
  -d '{

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Natural-language strings and comments present this as a "Chinese LLM Router" and the CLI test hardcodes a Chinese prompt, indicating a locale-specific behavior. The file does not offer a user choice or opt-in for language/locale, and no explicit justification for enforcing the Chinese locale is documented in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The router sends the full messages payload to external provider endpoints and includes a bearer token from configuration, which is a privacy- and credential-relevant network operation. While the header comment describes routing behavior, there is no user-facing confirmation, warning, or explicit disclosure near the transmission path or CLI test flow about sending conversation content to third-party providers.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 8)May include surrounding context.

md
{
    id: 'deepseek',
    name: 'DeepSeek',
    baseUrl: 'https://api.deepseek.com/v1',
    models: ['deepseek-chat', 'deepseek-reasoner'],
    signup: 'https://platform.deepseek.com',
    desc: 'Best open-source, cheapest flagship model'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/setup.js (reported line 18)May include surrounding context.

js
{
    id: 'deepseek',
    name: 'DeepSeek',
    baseUrl: 'https://api.deepseek.com/v1',
    models: ['deepseek-chat', 'deepseek-reasoner'],
    signup: 'https://platform.deepseek.com',
    desc: 'Best open-source, cheapest flagship model'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 32)May include surrounding context.

md
{
    id: 'kimi',
    name: 'Kimi (月之暗面/Moonshot)',
    baseUrl: 'https://api.moonshot.cn/v1',
    models: ['kimi-k2.5', 'kimi-k2.5-thinking', 'moonshot-v1-128k'],
    signup: 'https://platform.moonshot.cn',
    desc: 'Great long context & vision, open source'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/setup.js (reported line 42)May include surrounding context.

js
{
    id: 'kimi',
    name: 'Kimi (月之暗面/Moonshot)',
    baseUrl: 'https://api.moonshot.cn/v1',
    models: ['kimi-k2.5', 'kimi-k2.5-thinking', 'moonshot-v1-128k'],
    signup: 'https://platform.moonshot.cn',
    desc: 'Great long context & vision, open source'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 48)May include surrounding context.

md
{
    id: 'minimax',
    name: 'MiniMax',
    baseUrl: 'https://api.minimax.chat/v1',
    models: ['minimax-m2.5'],
    signup: 'https://platform.minimaxi.com',
    desc: 'Lightweight powerhouse, can run locally'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/setup.js (reported line 58)May include surrounding context.

js
{
    id: 'minimax',
    name: 'MiniMax',
    baseUrl: 'https://api.minimax.chat/v1',
    models: ['minimax-m2.5'],
    signup: 'https://platform.minimaxi.com',
    desc: 'Lightweight powerhouse, can run locally'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 56)May include surrounding context.

md
{
    id: 'step',
    name: 'Step (阶跃星辰)',
    baseUrl: 'https://api.stepfun.com/v1',
    models: ['step-3.5-flash', 'step-2-16k'],
    signup: 'https://platform.stepfun.com',
    desc: 'Blazing fast inference, trending on OpenRouter'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/setup.js (reported line 66)May include surrounding context.

js
{
    id: 'step',
    name: 'Step (阶跃星辰)',
    baseUrl: 'https://api.stepfun.com/v1',
    models: ['step-3.5-flash', 'step-2-16k'],
    signup: 'https://platform.stepfun.com',
    desc: 'Blazing fast inference, trending on OpenRouter'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 64)May include surrounding context.

md
{
    id: 'baichuan',
    name: 'Baichuan (百川)',
    baseUrl: 'https://api.baichuan-ai.com/v1',
    models: ['baichuan4-turbo'],
    signup: 'https://platform.baichuan-ai.com',
    desc: 'Strong Chinese language understanding'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/setup.js (reported line 74)May include surrounding context.

js
{
    id: 'baichuan',
    name: 'Baichuan (百川)',
    baseUrl: 'https://api.baichuan-ai.com/v1',
    models: ['baichuan4-turbo'],
    signup: 'https://platform.baichuan-ai.com',
    desc: 'Strong Chinese language understanding'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 78)May include surrounding context.

md
{
    id: 'hunyuan',
    name: 'Hunyuan (腾讯混元)',
    baseUrl: 'https://api.hunyuan.cloud.tencent.com/v1',
    models: ['hunyuan-turbo-s'],
    signup: 'https://cloud.tencent.com/product/hunyuan',
    desc: 'Tencent, WeChat ecosystem'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/setup.js (reported line 90)May include surrounding context.

js
{
    id: 'hunyuan',
    name: 'Hunyuan (腾讯混元)',
    baseUrl: 'https://api.hunyuan.cloud.tencent.com/v1',
    models: ['hunyuan-turbo-s'],
    signup: 'https://cloud.tencent.com/product/hunyuan',
    desc: 'Tencent, WeChat ecosystem'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script interactively collects API keys and persists them in plaintext JSON under the user's home directory without warning, permission hardening, or use of a secure secret store. Any local user, malware, backup system, or accidental file sharing that can read this file could recover provider credentials and use them to access paid APIs or sensitive prompts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.