amrouter
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
scripts/setup.shscript clones the application source code from an external, non-trusted GitHub repository (https://github.com/ahwanulm/AMRouter.git) into the user's local directory. - [COMMAND_EXECUTION]: The provided scripts (
setup.sh,scaffold-integration.sh) perform various system-level operations, including installing Node.js dependencies, building the frontend application, and generating project boilerplate. The skill also explicitly supports automation features using Playwright, 2Captcha, and temporary email services to bypass Cloudflare bot protections and automate account registration. - [INDIRECT_PROMPT_INJECTION]: As an AI gateway, the skill processes and routes untrusted user messages to multiple LLM providers, which creates an inherent risk of indirect prompt injection if the data is not properly handled by downstream agents.
- Ingestion points:
agent.js,agent.py,agent.shboilerplate scripts and the core gateway endpoints. - Capability inventory: Network requests to multiple external LLM APIs, local file writes for configuration and scaffolding.
- Sanitization: No explicit sanitization or filtering logic is provided in the gateway proxy code snippets.
- Boundary markers: None present in the routing instructions.
- [CREDENTIALS_UNSAFE]: The skill is designed to manage highly sensitive credentials, including API keys for over 50 LLM providers and administrative passwords. While the setup scripts follow best practices by generating random secrets and recommending
.envfiles, the concentration of these secrets in a single self-hosted gateway increases the impact of a potential compromise.
Audit Metadata