From 0c81cd5a1845a789a5432eb897cce1be59cbc09d Mon Sep 17 00:00:00 2001 From: Jack Pippett Date: Tue, 28 Apr 2026 12:25:07 -0700 Subject: [PATCH] security: gate litellm_skills proxy hook behind LITELLM_ENABLE_SKILLS env var The SkillsInjectionHook auto-registers in PROXY_HOOKS and executes model-generated Python code via SkillsSandboxExecutor without human confirmation. This makes the hook opt-in only by requiring LITELLM_ENABLE_SKILLS=true to be set explicitly. --- litellm/proxy/hooks/__init__.py | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/litellm/proxy/hooks/__init__.py b/litellm/proxy/hooks/__init__.py index 790ebcd8791..05ed6c87fd9 100644 --- a/litellm/proxy/hooks/__init__.py +++ b/litellm/proxy/hooks/__init__.py @@ -24,7 +24,6 @@ PROXY_HOOKS = { "parallel_request_limiter": _PROXY_MaxParallelRequestsHandler_v3, "cache_control_check": _PROXY_CacheControlCheck, "responses_id_security": ResponsesIDSecurity, - "litellm_skills": SkillsInjectionHook, "max_iterations_limiter": _PROXY_MaxIterationsHandler, "max_budget_per_session_limiter": _PROXY_MaxBudgetPerSessionHandler, } @@ -33,6 +32,9 @@ PROXY_HOOKS = { if os.getenv("LEGACY_MULTI_INSTANCE_RATE_LIMITING", "false").lower() == "true": PROXY_HOOKS["parallel_request_limiter"] = _PROXY_MaxParallelRequestsHandler +if os.getenv("LITELLM_ENABLE_SKILLS", "false").lower() == "true": + PROXY_HOOKS["litellm_skills"] = SkillsInjectionHook + ### update PROXY_HOOKS with ENTERPRISE_PROXY_HOOKS ###