iblai-router
Audited by Socket on Mar 7, 2026
1 alert found:
Obfuscated FileThe iblai-router skill presents a coherent purpose: a cost-optimizing routing proxy between OpenClaw and multiple model providers. The install/escalation workflow (copying files, systemd service, hot-reload) is consistent with a developer-focused proxy tool. However, several risk signals warrant caution: potential plaintext or insufficiently protected API keys stored in systemd/service configs when providers are switched, exposure of health/stats endpoints without authentication, and unclear TLS/secret-management practices. While none of the patterns prove malicious intent, the combination constitutes notable security considerations that should be addressed (secret management, endpoint access control, and explicit data-flow encryption assurances) before deploying in a production or multi-tenant environment.