Security audit
Poyo Tripo 3d
Security checks for vulnerabilities and agentic risk
Overview
This skill is a straightforward PoYo Tripo3D API helper that only submits user-prepared 3D generation requests when explicitly used.
Install only if you intend to use PoYo for Tripo3D generation. Keep POYO_API_KEY server-side, review payloads before submission, and avoid sending private prompts, confidential object images, private asset URLs, or callback URLs unless you are comfortable sharing them with PoYo and the callback receiver.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
