Security audit
Jev Router
Security checks for vulnerabilities and agentic risk
Overview
This plugin is a disclosed model-routing tool that sends bounded prompt excerpts to a Jev/OpenRouter classifier and can switch among administrator-approved models when enabled.
Install only if you are comfortable letting the plugin see current task prompts and send redacted excerpts to the configured classifier service, including in observe mode. Start in observe mode, use a small approved model pool, avoid exec-based secret sources unless you trust the command, and use the dashboard clear-history control if you do not want local routing records retained.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
