model-router

Warn

Audited by Socket on Feb 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

No evidence of explicit malicious code in the provided documentation; primary risks are operational and supply-chain: plaintext local credential storage, unpinned dependencies, and integration with an external CLI (sessions_spawn) that could forward credentials or data. Treat the package as functionally correct for routing tasks but requiring hardening before production use. Review implementation of setup-wizard and scripts that read .api-keys, ensure secrets are stored in a proper secret manager or encrypted at application level, pin dependencies, and audit any external integrations to confirm they do not exfiltrate secrets.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Feb 25, 2026, 02:48 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fmodel-router%2F@2673c4b19fd20353393af349b22cfab532d570e7