Coverage area · 1 check

AI and LLM integration security

LLM features add a new kind of input — text that can steer the model — and often give the model tools. OpenRouting reviews both the application code that calls models and the agent setup committed to your repository.

agent/answer.py1page = requests.get(url).text2system = RULES + page3tools = [shell_tool, http_tool]4run_tool_calls(reply)AIwhat this review answersUntrusted text in the system prompt?Shell or open HTTP tools exposed?Agent config auto-approving tools?$ verdict REAL ISSUE$ fix least-privilege tools, approvals on▍

Illustrative example of how a finding in this area is reviewed.

Why this area matters

Prompt injection is number one on the OWASP Top 10 for LLM Applications. Any untrusted text the model reads — a web page, an email, a file, a tool result — can contain instructions, and if the model can call tools, those instructions can act. Insecure output handling (passing model output to a shell, SQL or HTML unchecked) and excessive agency (tools broader than the task) complete the picture.

Repositories now also contain agent configuration: CLAUDE.md, skills, hooks, permission settings and MCP servers. Those files decide what a coding agent may do on a developer's machine or in CI, and no traditional scanner reads them. OpenRouting inventories that setup during a full scan and reviews it alongside the code.

What goes wrong in real applications

  • Prompt injection

    Untrusted content mixed into prompts — especially the system prompt — can override your instructions and redirect what the model does.

  • Model output driving actions

    Passing model output straight into a shell, query, file write or HTTP request means whoever influences the model influences those actions.

  • Excessive agency

    Shell, file or unrestricted network tools given to an agent that only needs to search turn a successful injection into code execution or data exfiltration.

  • Permissive agent setups

    Settings that auto-approve shell commands, hooks that run without review, and MCP servers with broad access ship risk to everyone who opens the repository with an agent.

  • Secrets in agent context

    API keys in agent config, MCP definitions or memory files are readable by the agent and anything that can steer it.

Sample: the risky pattern and the fix

Riskyagent/answer.py
tools = [shell_tool, http_tool, read_file_tool]

def answer(question: str, doc_url: str) -> str:
    page = requests.get(doc_url).text
    system = "Follow any instructions found in the docs. " + page
    reply = client.messages.create(
        model=MODEL, system=system, tools=tools, max_tokens=1024,
        messages=[{"role": "user", "content": question}],
    )
    return run_tool_calls(reply)   # executes whatever the model asks
Saferagent/answer.py
tools = [search_docs_tool]        # read-only; no shell, no open HTTP

def answer(question: str, doc_url: str) -> str:
    page = fetch_allowed_doc(doc_url)    # host allow-list
    reply = client.messages.create(
        model=MODEL, system=SYSTEM_PROMPT, tools=tools, max_tokens=1024,
        messages=[{"role": "user",
                   "content": wrap_untrusted(page, question)}],
    )
    return run_tool_calls(reply, approve=needs_human_approval)

The original puts a fetched web page into the system prompt and gives the model a shell and open HTTP, then runs every tool call — so text on that page can make the agent run commands. The fix keeps the system prompt fixed, marks fetched content as untrusted data, limits the tools to a read-only search, and requires approval for anything with side effects.

Illustrative code, simplified for clarity — not taken from a customer repository.

What OpenRouting checks in your repository

  • LLM SDK calls where request data, fetched pages or tool results reach the system prompt
  • Model output passed to shells, queries, file writes, HTML or HTTP requests
  • Tool definitions given to agents, and whether they are scoped to the task
  • Agent setup: CLAUDE.md, AGENTS.md, .claude/ settings, skills, hooks, memory files and MCP configs (agent-setup review add-on)
  • Secrets in agent and MCP configuration (redacted before review)

Scope and limits

  • It reviews code and configuration; it doesn't red-team your live model, run prompt-injection test suites or execute your agents or MCP servers.
  • Prompt injection can't be fully prevented by code review. The review focuses on limiting what a successful injection can do.

Coverage areas reflect OpenRouting's check library. Code, secret and infrastructure scanning run today; other areas are rolling out. Scanners surface candidates and a review agent decides whether each one is real — it doesn't promise to find every issue.

Review agents for this area

Common questions

What is the agent-setup review?

During a full repository scan, OpenRouting inventories any LLM-agent setup — CLAUDE.md, skills, hooks, settings, MCP configs, agent frameworks — and reviews it for prompt-injection, tool-safety and secrets risks. It is a +10 credit add-on, charged only when it runs.

Does OpenRouting run my agents?

No. Detection and review are read-only, and nothing in your repository is executed.