api-relay-audit — security grade SAFE, quality 72/100

Security audit verdict: SAFE · quality 72/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by toby-bridges · Agent Tool · ★ 865

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is api-relay-audit safe to install? View the security audit →

About api-relay-audit

API Relay Audit Local security audit for AI API relays and LLM proxies. ROADMAP · Engineering Diary · OpenClaw Skill · Hermes Skill What Is API Relay Audit? API Relay Audit is a local security audit tool for AI API relays and LLM proxies. It detects prompt injection, model substitution, tool rewriting, SSE anomalies, error leakage, and Web3 wallet risks while

ai-agentsai-auditai-securityanthropicapi-gatewayclaudedsh-pluginllm-auditllm-proxyllm-security

Quick Facts

Stars865
Forks82
LanguagePython
CategoryAgent Tool
LicenseAGPL-3.0
Quality Score71.7616464339154/100
Open Issues28
Last Updated2026-10-03
Created2026-03-30
Platformsbrowser, claude-code, python
Est. Tokens~15k

Compatible Skills

These tools work well together with api-relay-audit for enhanced workflows:

  • repo-forensics — semantic(0.43)+complementary+rare_topics+same_lang+similar_pop+shared_platform (79%)
  • plamen — semantic(0.53)+complementary+rare_topics+same_lang+similar_pop+shared_platform (78%)
  • agentseal — semantic(0.47)+complementary+same_lang+similar_pop+shared_platform (66%)
  • agent-audit — semantic(0.43)+complementary+same_lang+similar_pop+shared_platform (65%)
  • Semia — semantic(0.35)+complementary+same_lang+similar_pop+shared_platform (62%)

api-relay-audit alternative? Top 6 similar tools

Looking for a api-relay-audit alternative? If you're comparing api-relay-audit with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • hol-guard by hashgraph-online · ⭐ 728

    Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, M

  • linkedin-mcp-server by stickerdaniel · ⭐ 3.7k

    Open-source MCP server for LinkedIn. Give Claude and any MCP-compatible AI agent access to profiles, companies

  • kiro-gateway by jwadow · ⭐ 2.3k

    👻 Proxy API gateway for Kiro IDE & CLI (Amazon Q Developer / AWS CodeWhisperer). Use free Claude models with

  • skylos by duriantaco · ⭐ 828

    Open-source Python, TypeScript, and Go SAST with dead code detection. Finds secrets, exploitable flows, and

  • BambooAI by pgalko · ⭐ 791

    A Python library powered by Language Models (LLMs) for conversational data discovery and analysis.

  • maverick-mcp by wshobson · ⭐ 678

    MaverickMCP - Personal Stock Analysis MCP Server

More Agent Tool Tools

Explore other popular agent tool tools:

View all Agent Tool tools →

Popular Python Agent Tools

Frequently Asked Questions

What is api-relay-audit?

api-relay-audit is Local security audit for AI API relays and LLM proxies: detects prompt injection, model substitution, tool-call rewriting, SSE anomalies, error leakage, and Web3 wallet risks.. It is categorized as a Agent Tool with 865 GitHub stars.

What programming language is api-relay-audit written in?

api-relay-audit is primarily written in Python. It covers topics such as ai-agents, ai-audit, ai-security.

How do I install or use api-relay-audit?

You can find installation instructions and usage details in the api-relay-audit GitHub repository at github.com/toby-bridges/api-relay-audit. The project has 865 stars and 82 forks, indicating an active community.

What license does api-relay-audit use?

api-relay-audit is released under the AGPL-3.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to api-relay-audit?

The top alternatives to api-relay-audit on Agent Skills Hub include hol-guard, linkedin-mcp-server, kiro-gateway. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Agent Tool tools