Evidence snapshot reviewed Sep 5, 2026GitHub checked Aug 21, 2026
Source-reviewedStandalone SkillSecurity & GovernanceSecurity & Governance Profile

api-relay-audit

Audit a third-party AI API relay or proxy locally and generate an evidence-based risk report.

At a glance

What it does

Audit a third-party AI API relay or proxy locally and generate an evidence-based risk report.

Capabilities
Security & GovernanceSecurityAgentsTesting

Before you choose it

API Relay Audit runs a 14-step security review for AI API relays, gateways, proxies, and resale services. It checks for hidden prompt injection, model or tool-call substitution signals, context truncation, error leakage, stream anomalies, and optional Web3 wallet-safety behavior, then writes a Markdown report.

Best for

Developers and security-conscious agent users evaluating a third-party relay before sending coding, production, or wallet-sensitive traffic through it.

Common tasks

  • Assess a relay URL before relying on it for agent or coding traffic.
  • Investigate suspected prompt tampering, identity overrides, context truncation, or tool-call rewriting.
  • Run the Web3 or full profile for a wallet-sensitive relay workflow.

Permissions and data

Uses a relay API key and sends audit requests to the relay you configure.

Permissions
  • Read API_RELAY_AUDIT_KEY, API_RELAY_AUDIT_URL, and optional model/profile environment variables.
  • Run Python 3 and curl locally.
  • Make network requests to the configured relay and download the referenced audit script for the one-shot recipe.
Data handling
  • The skill instructs users not to print raw API keys in summaries, filenames, reports, shell traces, or comments.
  • Generated findings are written to a local Markdown report.
External services
  • The configured third-party AI API relay or proxy.
  • GitHub raw content for the referenced standalone audit script in the one-shot recipe.
Credentials
  • API_RELAY_AUDIT_KEY is required to run relay audits; a temporary or low-scope key is recommended.

Limitations

  • A no-finding result is not proof that a relay is safe.
  • The report is a technical audit result, not legal or security certification.
  • Some stream checks can be inconclusive for non-Anthropic relays or relays without thinking streams.
  • Aggressive error probes may create metered usage on pay-as-you-go relays.
  • The included license is AGPL-3.0-only.

What DSHub checked

  • The skill document is pinned to commit 00ce80208ea1178ac39116bf0843517a748e4dce.
  • The captured skill declares Linux, macOS, and Windows support and a Python 3 plus curl workflow.
  • The source contains instructions for a 14-step relay audit and Markdown report output.

What DSHub did not check

  • DSHub did not install or run this skill or its audit script.
  • Actual relay findings, service behavior, and audit cost depend on the target relay and selected options.

Pinned install

Primary action

This standalone skill does not have a DSH Plugin install action. Use its source documentation for the delivery method.

Visit the source project

Maintainer source

Skill instructions

View at commit 00ce802
Maintainer-authored contentCaptured from skills/api-relay-audit/SKILL.md on Sep 5, 2026. The text and repository-relative media are fixed to commit 00ce80208ea1 with content hash 2211d4f62c95; provider-hosted badges may update independently. SKILL.md commands are upstream documentation; use the type-correct primary action above and verify it against this pinned source.

name: api-relay-audit description: Use when auditing third-party AI API relays, LLM proxies, gateways, or API-key resale services locally before trusting coding, tool, production, or wallet-sensitive traffic. version: 2.4.0 author: Toby Bridges license: AGPL-3.0-only platforms: [linux, macos, windows] metadata: hermes: tags: [security, red-teaming, ai-safety, api-relay, web3] related_skills: [] required_environment_variables:

  • name: API_RELAY_AUDIT_KEY prompt: API relay key help: Use a temporary or low-scope key for the relay being tested. required_for: Running relay audits without pasting secrets into chat

API Relay Audit for Hermes Agent

Overview

This skill runs api-relay-audit, a zero-dependency 14-step security audit for third-party AI API relays and proxy services. It checks relay behavior while keeping API relay audit, prompt injection audit, model substitution signals, and Web3 relay audit as separate query families with separate evidence boundaries.

Use the standalone audit.py path by default. It only needs Python 3 and curl, which makes it suitable for local Hermes terminal sessions and sandboxed execution. On Windows, run the POSIX shell recipes from Git Bash or an equivalent shell; direct python audit.py ... invocations also work from PowerShell when the environment variables are set.

When to Use

  • The user asks whether an AI API relay, proxy API, resale key, or "API relay" is safe.
  • The user provides a relay base URL and wants an evidence-based risk report.
  • The user suspects hidden prompts, identity substitution, response tampering, context truncation, tool-call/package substitution, or stream anomalies.
  • The user wants to audit Web3/wallet safety behavior with --profile web3 or --profile full.

Do not use this skill for general model benchmarking, provider price comparison, or legal/security certification. The output is a technical audit report, not a guarantee that a service is safe.

Keep these query families separate:

Query family Use when Profile / evidence boundary
API relay audit The user wants a local report for a relay, mirror, gateway, LLM proxy, or resale API. Default general; report is evidence, not certification.
Prompt injection audit The user asks about hidden prompt injection, prompt leakage, instruction override, or extraction behavior. Steps 3-6; do not publish private prompts or secrets.
Model substitution signals The user suspects model identity, route, latency, or upstream channel mismatch. Signals from Steps 5, 10, 13, and 14 require corroboration; self-ID and fingerprints are not standalone provider proof.
Web3 relay audit The user is testing wallet-sensitive agent workflows. Use --profile web3 or --profile full; Step 11 is profile-gated.

Install or Share

After this file is merged to the public repository, Hermes users can install it as a tap skill:

hermes skills tap add toby-bridges/api-relay-audit
hermes skills install toby-bridges/api-relay-audit/api-relay-audit

For direct testing without adding the whole tap:

hermes skills install toby-bridges/api-relay-audit/skills/api-relay-audit

Required Inputs

Input How to provide it Notes
Relay API key Prefer $API_RELAY_AUDIT_KEY via Hermes secure env setup Use a temporary or low-scope key when possible.
Base URL Ask the user or use $API_RELAY_AUDIT_URL if already set Example: https://relay.example.com/v1.
Model Optional; default is claude-opus-4-6 Use the model the user plans to rely on.
Profile Optional; default is general Use web3 for wallet users, full for complete coverage.

Never print the raw API key in summaries, filenames, reports, shell traces, or GitHub comments. If the user pasted a key into chat, avoid repeating it and recommend rotating it after the audit if exposure matters.

Standard Workflow

  1. Confirm the target base URL, model, and profile.
  2. Ensure the key is available as $API_RELAY_AUDIT_KEY. If it is missing, ask the user to configure it through Hermes secure setup or local .env, not by committing it.
  3. Download the standalone script into a temporary directory unless the current repo already contains audit.py.
  4. Run the audit and write a Markdown report.
  5. Summarize only evidence from the generated report. Do not overstate safety or make policy promises.

One-Shot Audit Recipe

Use this when the user provides a base URL and wants a normal audit:

This recipe is POSIX shell. On Windows Hermes hosts, use Git Bash for this one-shot form; if the repository already has audit.py, PowerShell can run the direct local command shown after the recipe.

set -euo pipefail

: "${API_RELAY_AUDIT_KEY:?Set API_RELAY_AUDIT_KEY through Hermes secure env setup first}"
: "${API_RELAY_AUDIT_URL:?Set API_RELAY_AUDIT_URL to the relay base URL}"

MODEL="${API_RELAY_AUDIT_MODEL:-claude-opus-4-6}"
PROFILE="${API_RELAY_AUDIT_PROFILE:-general}"
WORKDIR="$(mktemp -d)"
REPORT="$PWD/api-relay-audit-report.md"
AUDIT_SCRIPT_REF=v2.4.0

curl -fsSL \
  "https://raw.githubusercontent.com/toby-bridges/api-relay-audit/${AUDIT_SCRIPT_REF}/audit.py" \
  -o "$WORKDIR/audit.py"

python3 "$WORKDIR/audit.py" \
  --key "$API_RELAY_AUDIT_KEY" \
  --url "$API_RELAY_AUDIT_URL" \
  --model "$MODEL" \
  --profile "$PROFILE" \
  --output "$REPORT"

printf 'Report written to %s\n' "$REPORT"

If the current working tree is the api-relay-audit repository and audit.py exists, prefer the local file:

python3 audit.py \
  --key "$API_RELAY_AUDIT_KEY" \
  --url "$API_RELAY_AUDIT_URL" \
  --model "${API_RELAY_AUDIT_MODEL:-claude-opus-4-6}" \
  --profile "${API_RELAY_AUDIT_PROFILE:-general}" \
  --output api-relay-audit-report.md

Profiles and Cost Controls

Scenario Recommended flags
Fast first pass --skip-infra --skip-context --skip-latency-variance
Normal relay audit --profile general
Web3 or wallet relay --profile web3
Complete audit --profile full
Suspicious relay with request-count gating --warmup 5 to --warmup 20
Avoid intentionally broken requests --skip-error-leakage
Avoid streaming checks --skip-stream-integrity
Avoid upstream channel classification --skip-channel-classifier

Warn the user before enabling --aggressive-error-probes because oversized probes can create metered usage on pay-as-you-go relays.

What the 14 Steps Cover

Step Area Purpose
1 Infrastructure recon DNS, WHOIS, SSL, HTTP headers, and panel hints.
2 Model list Available models, model count, and ownership fields.
3 Token injection Hidden system-prompt size via token delta.
4 Prompt extraction Direct attempts to extract hidden prompts.
5 Instruction conflict and identity Whether user instructions and identity settings are overridden.
6 Jailbreak extraction Indirect prompt-extraction attempts.
7 Context length Canary-based truncation detection.
8 Tool-call substitution Package-install command rewriting, AC-1.a.
9 Error leakage Credential, header, stack trace, path, and internal-field leakage.
10 Stream integrity SSE event whitelist, usage monotonicity, signatures, terminal message_stop completeness, and stream model identity.
11 Web3 prompt injection Wallet-safety refusal probes, profile-gated.
12 Infrastructure fingerprint Known relay framework signatures, informational only.
13 Latency variance Bimodal or unstable routing hints, informational only.
14 Upstream channel classifier Bedrock, Vertex, OpenRouter, Cloudflare AI Gateway, or transparent Anthropic relay hints from headers, message IDs, and body signals.

Report Summary Template

After running the audit, summarize in this format:

## Audit Result: <relay host>

Overall risk: LOW / MEDIUM / HIGH

- Token injection: <delta or unavailable>
- Prompt extraction: <count or summary>
- User control: <instruction/identity result>
- Context length: <full/truncated/inconclusive>
- Tool-call substitution: <clean/substituted/inconclusive>
- Error leakage: <none/medium/high/critical/inconclusive>
- Stream integrity: <clean/anomaly/inconclusive>
- Upstream channel: <direct/known channel/transparent/inconclusive>
- Web3 profile: <not run/clean/injected/inconclusive>
- Informational: <infra fingerprint and latency variance highlights>

Recommendation: <use / use with caution / do not use>, based only on the report evidence.

Common Pitfalls

  1. Do not treat "no finding" as proof of safety. It only means these probes did not catch tampering.
  2. Do not paste or repeat API keys in chat. Prefer API_RELAY_AUDIT_KEY.
  3. Do not skip dual-distribution context when editing the project itself: changes to modular audit logic usually need root audit.py parity.
  4. Do not promise product timelines, vendor cooperation, or risk-policy changes from an audit result.
  5. If a relay is non-Anthropic or does not support thinking streams, Step 10 may be inconclusive rather than clean.

Verification Checklist

  • skills/api-relay-audit/SKILL.md frontmatter has name, description, version, author, license, and metadata.hermes.tags.
  • Description is under 1024 characters and starts with "Use when".
  • The audit command uses $API_RELAY_AUDIT_KEY, not a literal key.
  • The report was generated as Markdown and the key was not echoed.
  • Any public reply or GitHub comment is grounded only in the report, README, ROADMAP, FOR_JOHN, or current code.

Operate deliberately

Install and manage

Prerequisites and target Profile

Target Security & Governance Profile

Delivery Skill Files — https://raw.githubusercontent.com/toby-bridges/api-relay-audit/00ce80208ea1178ac39116bf0843517a748e4dce/skills/api-relay-audit/SKILL.md

Compatibility and access

Linux, macOS, and Windows; requires Python 3 and curl Not declared in supplied evidence

Review compatibility evidence

Risk facts

Credential

Requires an API relay key; use a temporary or low-scope key and do not paste it into chat or reports.

Evidence
External Network Activity

Audit probes contact the configured third-party relay and can incur metered usage; aggressive error probes need an explicit warning.

Evidence
License

Licensed under AGPL-3.0-only.

Evidence
Evidence and editorial reviewManifest, Bundle patch, distribution and freshness

Immutable evidence

Review status and source activity

Human approved

Approved for publication after reviewing the source-linked content and immutable release record. AI assisted with the draft; the publication decision was human.

Human reviewed Sep 5, 2026, 5:24 PM UTCGitHub facts last checked Sep 5, 2026, 4:31 PM UTC

No material source change has been recorded since this evidence baseline.

Next step

Compare ecosystem artifact types

Subscribe to material changes for api-relay-audit