loka-ai-router — install-time binary downloads and shell installers
A real local AI router with dangerous install hygiene: postinstall pulls executables and a setup path runs curl | sh. Not malware — the risk is to the tool's own users.
loka-ai-router is a genuine, open-source local AI router (repo noxaascript/Loka) — it proxies OAuth + API keys for many AI providers (OpenAI, Anthropic, Google, Groq, xAI, OpenRouter, Perplexity, Hugging Face, …) and serves on localhost:8787. Its outbound traffic is first-party only (the providers' own OAuth/API endpoints plus GitHub/npm) and the tokens it handles are stored locally. We found no exfiltration and no backdoor.
It is listed here as Risky tool, not malware or abuse: the concern is install-time hygiene that puts the tool's own users at risk.
On npm install the postinstall hook (scripts/postinstall.mjs) silently downloads executables — cloudflared and rtk — into ~/.local/share/loka/bin.
A setup path (lib/api/token-saver.js) installs tooling by running curl -fsSL https://raw.githubusercontent.com/rtk-ai/rtk/.../install.sh | sh and npm install -g @caveman-ai/cli, and writes into ~/.claude/skills/caveman.
Each of these is from an official source, but auto-downloading binaries at install time and piping a remote script straight into a shell are classic supply-chain footguns: a compromise of any upstream (or a MITM) becomes code execution on every install, with no review step.
postinstall → postinstall.mjs downloads cloudflared + rtk release binariescurl -fsSL …rtk/install.sh | sh (remote script piped to shell)npm install -g @caveman-ai/cli (global install)~/.claude/skills/caveman (Claude Code skill integration)Explicitly not malware or abuse tooling: no theft, no backdoor, first-party-only network, local token storage. Catalogued as a Risky tool so the install-time hygiene is visible to its users; excluded from the OSV outputs by design.