Local security audit of AI API relay and LLM agent
toby-bridges/api-relay-audit · skills
Local security audit for AI API relays and LLM proxies: detects prompt injection, model substitution, tool-call rewriting, SSE anomalies, error leakage, and Web3 wallet risks.
★ 824GitHub stars
77Forks
2026-08-23Last updated
PythonLanguage
AGPL-3.0License
Key features
- It does not certify that a relay is safe.
- Prompt injection means the relay may prepend or insert hidden instructions into your request.
- With the web3 or full profile, API Relay Audit checks transfer guidance, signed-transaction refusal, and private-key refusal behavior before wallet-related traffic is trusted.
- Inconclusive means the tool could not determine a clean or anomalous result for that step.
- It does not replace manual security review or operational monitoring.
Install command
dsh plugin --profile web add github:toby-bridges/api-relay-audit