External Transmission
- Category
- Data Exfiltration
- Confidence
- 93% confidence
- Finding
The skill instructs the agent to send user prompts and API credentials to an external service at api.vapagent.com. This is a real external data transmission risk because prompts, media URLs, and the bearer token leave the local environment and are sent to a third-party API; if sensitive data is included in prompts or referenced URLs, it could be exposed outside the agent platform.
- Content
Create Generation
bash curl -s -X POST https://api.vapagent.com/api/v1/generations \ -H "Authorization: Bearer $VAP_API_KEY" \ -H "Content-Type: application/json" \ -d '{"kind":"image","prompt":"PROMPT","params":{"aspect_ratio":"1:1"}}'
