codexsaver-cost-router
Warn
Audited by Socket on May 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s core behavior is broadly aligned with cost-aware LLM routing, but its trust chain is weaker than claimed because installation comes from a mutable GitHub repo owned by a different entity than the stated publisher. Data flows and credential use are mostly proportionate, yet the repo-installed MCP tool receives API keys and code context and forwards them to third-party model providers, creating meaningful supply-chain and data exposure risk.
Confidence: 86%Severity: 72%
Audit Metadata