Back to skill

Security audit

Model Router Manager

Security checks for vulnerabilities and agentic risk

Overview

The skill is not malicious, but it materially overstates automatic routing, failover, and cost-monitoring capabilities that the included script does not implement.

Install only if you want a lightweight local configuration helper, not a proven automatic router. Treat the advertised failover, cost savings, statistics, and API integration as unverified until implemented or tested, and avoid placing API keys in unprotected config files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill appears to overstate its capabilities: it claims automatic model routing, failover, cost optimization, and statistics, but the analysis indicates the implementation only stores configuration and reads local fields without performing the advertised runtime behavior. This is dangerous because users may rely on nonexistent routing, failover, or monitoring controls in production, causing silent reliability, cost, or data-handling failures; the undocumented local config file access also weakens informed consent and auditability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README promotes automatic routing and failover across multiple third-party model providers, which implies user prompts and possibly sensitive data may be transmitted to alternate external services without the user's explicit awareness. In a routing manager, silent provider switching changes the data-processing boundary and can create confidentiality, compliance, and data residency risks if operators assume requests stay with a single vendor.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documentation references API keys and external model platforms but omits guidance on secure credential storage, scope, rotation, and configuration sensitivity. This can lead users to place secrets in unsafe config files, logs, or shell history, which is especially risky in a routing tool that may aggregate credentials for several providers at once.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The API integration examples encourage routing prompts through third-party model providers but do not warn that user prompts, attachments, and related metadata may be transmitted externally. In a model-router skill, this context makes the omission more significant because the core function is to forward requests across multiple providers, increasing the chance of unintended data disclosure or policy noncompliance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This is a manifest file, so vague-trigger review applies. The description says the skill 'automatically selects the optimal model' but does not define when it should activate, what requests it applies to, or any exclusions, which can lead to unintended invocation from broad model-selection contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description is written only in Chinese, which may impose a language/locale constraint on users without offering choice or documenting a region-specific justification. The policy requires language constraints to be opt-in or clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README content is presented almost entirely in Chinese, and it does not indicate that the skill is region-specific or provide an alternative language option. This can violate a language/locale policy when users are forced into a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description field is in Chinese, and much of the user-facing documentation is likewise Chinese, but the file does not offer an explicit language/locale option or explain that the skill is intentionally region-specific. Per the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Most headings, examples, command explanations, and troubleshooting guidance are presented only in Chinese, which can effectively force a locale on users. The file does not indicate that this is a region-specific skill or provide an alternative language option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This shell script contains natural-language help text and operational messages entirely in Chinese, including usage instructions and command descriptions. Under the policy, forcing a specific language without user opt-in or an explicitly justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.