Poyo Meshy 6 3d

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward PoYo/Meshy 6 helper that uses a disclosed API key and API call for user-requested 3D asset generation.

Install only if you intend to send prompts, image URLs, callback URLs, and generated asset metadata to PoYo. Keep POYO_API_KEY server-side, avoid logging private request data, and only allow live submissions when you explicitly want the agent to create a PoYo job.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
75% confidence
Finding
The skill advertises and operationalizes shell capability via curl in metadata and execution guidance, but the static finding indicates no corresponding declared permissions. That mismatch can bypass expected trust and review boundaries, making it easier for an agent to perform networked shell actions that operators did not explicitly authorize.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal