Back to skill

Security audit

Poyo Claude Opus 4 8

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward PoYo Claude API helper that sends user-prepared payloads to PoYo only when invoked, with the API key requirement disclosed.

Install only if you intend to use PoYo for Claude Opus 4.8 API calls. Keep POYO_API_KEY server-side, review payload JSON before submitting it, and avoid sending private prompts, user data, images, or tool inputs unless your policy allows that data to be sent to PoYo.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api.md (reported line 19)May include surrounding context.

Content-Type: application/json

text

Get API keys from <https://poyo.ai/dashboard/api-key>.

Recommended skill env var:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares shell capability via required curl usage and references an executable script, but it does not declare any explicit tool scope such as permissions or allowed-tools. That omission weakens least-privilege controls and can let an agent invoke broader shell functionality than the skill metadata makes clear, especially in environments that rely on manifest-level tool restrictions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 56)May include surrounding context.

Basic Messages Example

bash
curl --fail-with-body --request POST \
  --url "https://api.poyo.ai/v1/messages" \
  --header "x-api-key: YOUR_API_KEY" \
  --header "anthropic-version: 2023-06-01" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/submit_claude_opus_4_8_messages.sh (reported line 13)May include surrounding context.

sh
payload_file="$1"

curl --fail-with-body --request POST \
  --url "https://api.poyo.ai/v1/messages" \
  --header "x-api-key: ${POYO_API_KEY}" \
  --header "anthropic-version: 2023-06-01" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This shell script performs an HTTP POST to an external API and includes both the contents of a user-supplied JSON file and a credential header. Within the code, there is no confirmation prompt, logging, comment, or other user-facing disclosure explaining that local data will be sent off-host to api.poyo.ai.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
payload_file="$1"

curl --fail-with-body --request POST \
  --url "https://api.poyo.ai/v1/messages" \
  --header "x-api-key: ${POYO_API_KEY}" \
  --header "anthropic-version: 2023-06-01" \
  --header "Content-Type: application/json" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 5)May include surrounding context.

md
payload_file="$1"

curl --fail-with-body --request POST \
  --url "https://api.poyo.ai/v1/messages" \
  --header "x-api-key: ${POYO_API_KEY}" \
  --header "anthropic-version: 2023-06-01" \
  --header "Content-Type: application/json" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 57)May include surrounding context.

md
payload_file="$1"

curl --fail-with-body --request POST \
  --url "https://api.poyo.ai/v1/messages" \
  --header "x-api-key: ${POYO_API_KEY}" \
  --header "anthropic-version: 2023-06-01" \
  --header "Content-Type: application/json" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 78)May include surrounding context.

md
payload_file="$1"

curl --fail-with-body --request POST \
  --url "https://api.poyo.ai/v1/messages" \
  --header "x-api-key: ${POYO_API_KEY}" \
  --header "anthropic-version: 2023-06-01" \
  --header "Content-Type: application/json" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 116)May include surrounding context.

md
payload_file="$1"

curl --fail-with-body --request POST \
  --url "https://api.poyo.ai/v1/messages" \
  --header "x-api-key: ${POYO_API_KEY}" \
  --header "anthropic-version: 2023-06-01" \
  --header "Content-Type: application/json" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/submit_claude_opus_4_8_messages.sh (reported line 14)May include surrounding context.

sh
payload_file="$1"

curl --fail-with-body --request POST \
  --url "https://api.poyo.ai/v1/messages" \
  --header "x-api-key: ${POYO_API_KEY}" \
  --header "anthropic-version: 2023-06-01" \
  --header "Content-Type: application/json" \

Static analysis

No suspicious patterns detected.