Back to skill

Security audit

Poyo Kling 1 6

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward PoYo Kling 1.6 video-generation helper that discloses its API-key and network use.

Install only if you intend to use PoYo for Kling 1.6 generation. Keep POYO_API_KEY in a server-side environment, review payloads before submission, and avoid sending private prompts, source images, or callback URLs unless you trust PoYo and the callback receiver.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding
The skill advertises operational shell capability via curl and a submission script, but the manifest does not declare permissions for that capability. This creates a transparency and policy gap: an agent or reviewer may underestimate what the skill can do, including making outbound requests with sensitive prompt data or secrets.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.