Hi - I answer from the OpenSmartRoute documentation: routing, the API, plans and quotas, self-hosting. Ask away, or open a support ticket if you need a person.
Grounded in the docs - follow a source before acting on it.
security - Skill - OpenSmartRoute
Skillv1.0.0
security
Use when changing dependency definitions, command execution, file handling, evidence capture, report content, CI security scanning, or anything with security impact. Covers Snyk, SonarQube, redaction,
Instruction file imported from kpeacocke/attest (.github/instructions/security.instructions.md). Copyright stays with the author.
Security Guidance
Run or request Snyk scanning for new or changed first-party code and dependency updates where the tooling is available.
Review SonarQube findings for changed files and fix newly introduced security or maintainability issues.
Treat command execution, file parsing, and report generation as hostile-input surfaces.
Redact or truncate secrets, credentials, tokens, private keys, and sensitive host evidence.
Prefer safe standard-library helpers over shelling out.
Validate paths and inputs before reading files, invoking commands, or writing artefacts.
Do not add broad ignore rules or suppress findings unless the rationale is documented.
Use it
Copy one of these into your project. Installing also returns the manifest and these snippets.
# after Install: the listing is in your workspace's routing pool - a plan picks it for its slot
curl -s -X POST https://api.opensmartroute.ai/api/v1/route -H 'Authorization: Bearer $OSR_API_KEY' -H 'Content-Type: application/json' -d '{"text": "...", "plan": true}'
Manifest
An Open Capability Manifest: the router reads it to know what this does, what it costs and when to pick it.