openrouter-routing-rules

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements model routing strategies that analyze user prompt content (e.g., searching for keywords like 'code', 'json', or 'story') to decide which LLM to invoke. This provides an attack surface where input values can programmatically influence routing decisions.- [EXTERNAL_DOWNLOADS]: Recommends the use of the well-known openai Python SDK and connects to the OpenRouter API service at openrouter.ai. It also references documentation from the vendor's official sites jeremylongshore.com and intentsolutions.io.- [CREDENTIALS_UNSAFE]: Uses best practices for authentication by requiring the OpenRouter API key to be provided through common environment variables (OPENROUTER_API_KEY) rather than hardcoding static secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:46 AM
Security Audit — agent-trust-hub — openrouter-routing-rules