⚠ Medium — Risky tool Analyzed 2026-10-01 · UTC
A security-hygiene observation, not a malware finding. This advisory documents dangerous security practices in a legitimate-purpose tool — for example transmitting credentials over plaintext HTTP, heavy code obfuscation, or automatic global installs. It is not a claim of theft, backdoor or malicious intent: the tool does what it advertises, and the risk falls on its own users and their data. It is published so operators can make an informed decision before installing or deploying it.
Advisory · CLR-2026-3063

loka-ai-router — install-time binary downloads and shell installers

A real local AI router with dangerous install hygiene: postinstall pulls executables and a setup path runs curl | sh. Not malware — the risk is to the tool's own users.

Risky toolMediumnpm
What it is

loka-ai-router is a genuine, open-source local AI router (repo noxaascript/Loka) — it proxies OAuth + API keys for many AI providers (OpenAI, Anthropic, Google, Groq, xAI, OpenRouter, Perplexity, Hugging Face, …) and serves on localhost:8787. Its outbound traffic is first-party only (the providers' own OAuth/API endpoints plus GitHub/npm) and the tokens it handles are stored locally. We found no exfiltration and no backdoor.

It is listed here as Risky tool, not malware or abuse: the concern is install-time hygiene that puts the tool's own users at risk.

Why it is risky

On npm install the postinstall hook (scripts/postinstall.mjs) silently downloads executables — cloudflared and rtk — into ~/.local/share/loka/bin.

A setup path (lib/api/token-saver.js) installs tooling by running curl -fsSL https://raw.githubusercontent.com/rtk-ai/rtk/.../install.sh | sh and npm install -g @caveman-ai/cli, and writes into ~/.claude/skills/caveman.

Each of these is from an official source, but auto-downloading binaries at install time and piping a remote script straight into a shell are classic supply-chain footguns: a compromise of any upstream (or a MITM) becomes code execution on every install, with no review step.

Install-time behaviours
⚙️postinstall → postinstall.mjs downloads cloudflared + rtk release binaries
🧪setup runs curl -fsSL …rtk/install.sh | sh (remote script piped to shell)
📦setup runs npm install -g @caveman-ai/cli (global install)
📝writes ~/.claude/skills/caveman (Claude Code skill integration)
✅No exfiltration: network is first-party AI-provider/tooling endpoints only; tokens stored locally
If you use it
#ActionPriority
1 Install with --ignore-scripts and fetch/verify cloudflared and rtk yourself from their official releases. Recommended
2 Review scripts/postinstall.mjs and lib/api/token-saver.js before trusting an auto-install on a shared or CI host. Recommended

Explicitly not malware or abuse tooling: no theft, no backdoor, first-party-only network, local token storage. Catalogued as a Risky tool so the install-time hygiene is visible to its users; excluded from the OSV outputs by design.