What it does
Local security audit for AI API relays and LLM proxies: detects prompt injection, model substitution, tool-call rewriting, SSE anomalies, error leakage, and Web3 wallet risks.
Installation
dsh plugin --profile web add github:toby-bridges/api-relay-auditInstall method: GitHub · not yet tested in container (L3+)
Compatibility
| DSH Version | Status |
|---|---|
| not stated | Declared — not tested |
Requirements
- • Node.js: not stated
- • DSH: declared "not stated"
- • External credentials: none detected
Security Report
Automated static scan, not manual review.
No critical or warning findings in the automated scan. The result is valid only for the commit hash shown.
2.4.0dsh manifest00ce80208ea12026-08-1800ce80208ea1The scan result is only valid for the scanned commit. If the latest commit differs, the badge shows outdated until the daily pipeline rescans.
Disclaimer: automated static analysis, not a security guarantee. Always review what you install.
• Static heuristic scan: done (15 files)
• Dependency vulnerabilities: requires deep audit (L3+)
• Permission sandboxing: requires runtime testing (L4+)
Scan findings · 2
- infoHardcoded IP addressapi_relay_audit/_transport.py:16LOOPBACK_NO_PROXY = "localhost,127.0.0.1,::1"
- infoHardcoded IP addressapi_relay_audit/_transport.py:17LOOPBACK_HOSTS = {"localhost", "127.0.0.1", "::1"}
Heuristic static scan — may produce false positives. Review the source yourself before trusting.
Activity
Last commit 2026-08-15 · activity: Active
• Repo created: 2026-08-18
• Stars: ★ 791 · Forks: 76
• Health: Active — committed within last 30 days
