Coverage area · 1 check
AI and LLM integration security
LLM features add a new kind of input — text that can steer the model — and often give the model tools. OpenRouting reviews both the application code that calls models and the agent setup committed to your repository.
Illustrative example of how a finding in this area is reviewed.
Why this area matters
Prompt injection is number one on the OWASP Top 10 for LLM Applications. Any untrusted text the model reads — a web page, an email, a file, a tool result — can contain instructions, and if the model can call tools, those instructions can act. Insecure output handling (passing model output to a shell, SQL or HTML unchecked) and excessive agency (tools broader than the task) complete the picture.
Repositories now also contain agent configuration: CLAUDE.md, skills, hooks, permission settings and MCP servers. Those files decide what a coding agent may do on a developer's machine or in CI, and no traditional scanner reads them. OpenRouting inventories that setup during a full scan and reviews it alongside the code.
What goes wrong in real applications
Prompt injection
Untrusted content mixed into prompts — especially the system prompt — can override your instructions and redirect what the model does.
Model output driving actions
Passing model output straight into a shell, query, file write or HTTP request means whoever influences the model influences those actions.
Excessive agency
Shell, file or unrestricted network tools given to an agent that only needs to search turn a successful injection into code execution or data exfiltration.
Permissive agent setups
Settings that auto-approve shell commands, hooks that run without review, and MCP servers with broad access ship risk to everyone who opens the repository with an agent.
Secrets in agent context
API keys in agent config, MCP definitions or memory files are readable by the agent and anything that can steer it.
Sample: the risky pattern and the fix
tools = [shell_tool, http_tool, read_file_tool]
def answer(question: str, doc_url: str) -> str:
page = requests.get(doc_url).text
system = "Follow any instructions found in the docs. " + page
reply = client.messages.create(
model=MODEL, system=system, tools=tools, max_tokens=1024,
messages=[{"role": "user", "content": question}],
)
return run_tool_calls(reply) # executes whatever the model askstools = [search_docs_tool] # read-only; no shell, no open HTTP
def answer(question: str, doc_url: str) -> str:
page = fetch_allowed_doc(doc_url) # host allow-list
reply = client.messages.create(
model=MODEL, system=SYSTEM_PROMPT, tools=tools, max_tokens=1024,
messages=[{"role": "user",
"content": wrap_untrusted(page, question)}],
)
return run_tool_calls(reply, approve=needs_human_approval)The original puts a fetched web page into the system prompt and gives the model a shell and open HTTP, then runs every tool call — so text on that page can make the agent run commands. The fix keeps the system prompt fixed, marks fetched content as untrusted data, limits the tools to a read-only search, and requires approval for anything with side effects.
Illustrative code, simplified for clarity — not taken from a customer repository.
What OpenRouting checks in your repository
- LLM SDK calls where request data, fetched pages or tool results reach the system prompt
- Model output passed to shells, queries, file writes, HTML or HTTP requests
- Tool definitions given to agents, and whether they are scoped to the task
- Agent setup: CLAUDE.md, AGENTS.md, .claude/ settings, skills, hooks, memory files and MCP configs (agent-setup review add-on)
- Secrets in agent and MCP configuration (redacted before review)
Scope and limits
- It reviews code and configuration; it doesn't red-team your live model, run prompt-injection test suites or execute your agents or MCP servers.
- Prompt injection can't be fully prevented by code review. The review focuses on limiting what a successful injection can do.
Coverage areas reflect OpenRouting's check library. Code, secret and infrastructure scanning run today; other areas are rolling out. Scanners surface candidates and a review agent decides whether each one is real — it doesn't promise to find every issue.
Review agents for this area
- AI / LLM safety — Checks LLM application code for prompt injection and unsafe handling of model output.
- Agent setup reviewer
- Secrets & data exposure — Judges whether a flagged value is really a secret and whether sensitive data leaks through logs or errors.
Common questions
What is the agent-setup review?
During a full repository scan, OpenRouting inventories any LLM-agent setup — CLAUDE.md, skills, hooks, settings, MCP configs, agent frameworks — and reviews it for prompt-injection, tool-safety and secrets risks. It is a +10 credit add-on, charged only when it runs.
Does OpenRouting run my agents?
No. Detection and review are read-only, and nothing in your repository is executed.