api-providers

Warn

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: MEDIUMPERSISTENCECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PERSISTENCE]: The SETUP.md file contains a command to establish an hourly cron job that executes the refresh.ts script. This mechanism ensures the script runs periodically in the background to update the provider registry.
  • [COMMAND_EXECUTION]: The refresh.ts script invokes the system's pass utility using execFileSync to retrieve API keys from the GPG password store. This allows the script to access local secrets based on paths defined in the user's models.json configuration.
  • [DATA_EXFILTRATION]: The skill implements a data flow where sensitive credentials (API keys) are retrieved from a local store and sent as authorization headers in network requests to various external LLM providers (e.g., Anthropic, OpenRouter, and others). This satisfies the pattern of reading sensitive data and transmitting it to remote services, although it is the intended function of the registry.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to its handling of external data.
  • Ingestion points: Data is ingested from ~/vault/api/models.json and from the JSON responses of external provider model-list APIs (via fetch in refresh.ts).
  • Boundary markers: The script does not utilize boundary markers or explicit delimiters when constructing the PROVIDERS.md markdown file from external data.
  • Capability inventory: The script can perform network requests (fetch), write to local files (writeFileSync), and execute CLI commands (pass show).
  • Sanitization: The script performs minimal validation or escaping of the model metadata (IDs, statuses, notes) retrieved from external sources before embedding them into the markdown documentation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 20, 2026, 08:52 PM
Security Audit — agent-trust-hub — api-providers