Back to skill

Security audit

Poyo Wan Animate

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward PoYo Wan Animate helper that uses a disclosed API key and user-provided media URLs to submit video generation jobs.

Use this skill only if you intend to send video and image URLs to PoYo for generation. Keep POYO_API_KEY in a server-side environment, expect API usage to consume credits or incur costs, and avoid submitting private likenesses, private videos, or sensitive callback URLs unless you trust PoYo and have the needed consent.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.