api-providers
Warn
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: MEDIUMPERSISTENCECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PERSISTENCE]: The
SETUP.mdfile contains a command to establish an hourly cron job that executes therefresh.tsscript. This mechanism ensures the script runs periodically in the background to update the provider registry. - [COMMAND_EXECUTION]: The
refresh.tsscript invokes the system'spassutility usingexecFileSyncto retrieve API keys from the GPG password store. This allows the script to access local secrets based on paths defined in the user'smodels.jsonconfiguration. - [DATA_EXFILTRATION]: The skill implements a data flow where sensitive credentials (API keys) are retrieved from a local store and sent as authorization headers in network requests to various external LLM providers (e.g., Anthropic, OpenRouter, and others). This satisfies the pattern of reading sensitive data and transmitting it to remote services, although it is the intended function of the registry.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to its handling of external data.
- Ingestion points: Data is ingested from
~/vault/api/models.jsonand from the JSON responses of external provider model-list APIs (viafetchinrefresh.ts). - Boundary markers: The script does not utilize boundary markers or explicit delimiters when constructing the
PROVIDERS.mdmarkdown file from external data. - Capability inventory: The script can perform network requests (
fetch), write to local files (writeFileSync), and execute CLI commands (pass show). - Sanitization: The script performs minimal validation or escaping of the model metadata (IDs, statuses, notes) retrieved from external sources before embedding them into the markdown documentation.
Audit Metadata