Back to skill

Security audit

Poyo Tripo 3d

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward PoYo Tripo3D API helper that only submits user-prepared 3D generation requests when explicitly used.

Install only if you intend to use PoYo for Tripo3D generation. Keep POYO_API_KEY server-side, review payloads before submission, and avoid sending private prompts, confidential object images, private asset URLs, or callback URLs unless you are comfortable sharing them with PoYo and the callback receiver.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.