Back to skill

Security audit

VAP Media API skill for Realistic image video music

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward VAP Media API helper that sends prompts and media URLs to VAP only when performing the requested media generation or editing work.

Install this only if you are comfortable sending media prompts, task metadata, and any referenced media URLs to VAP using your VAP_API_KEY. Avoid submitting confidential prompts, private signed URLs, regulated data, or sensitive media unless VAP's terms and your own data-handling requirements allow it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (14)

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The skill instructs the agent to send user prompts and API credentials to an external service at api.vapagent.com. This is a real external data transmission risk because prompts, media URLs, and the bearer token leave the local environment and are sent to a third-party API; if sensitive data is included in prompts or referenced URLs, it could be exposed outside the agent platform.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

Create Generation

bash
curl -s -X POST https://api.vapagent.com/api/v1/generations \
  -H "Authorization: Bearer $VAP_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"kind":"image","prompt":"PROMPT","params":{"aspect_ratio":"1:1"}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The skill instructs the agent to send user prompts and API credentials to an external service at api.vapagent.com. This is a real external data transmission risk because prompts, media URLs, and the bearer token leave the local environment and are sent to a third-party API; if sensitive data is included in prompts or referenced URLs, it could be exposed outside the agent platform.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

Create Generation

bash
curl -s -X POST https://api.vapagent.com/api/v1/generations \
  -H "Authorization: Bearer $VAP_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"kind":"image","prompt":"PROMPT","params":{"aspect_ratio":"1:1"}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

Polling the generation status endpoint transmits the bearer token and task identifier to an external service. Although lower risk than creation requests, it still confirms continued authenticated communication with a third-party API and could leak metadata about user activity if mishandled.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Poll Generation

bash
curl -s https://api.vapagent.com/api/v1/generations/GENERATION_ID \
  -H "Authorization: Bearer $VAP_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The operation endpoint sends externally hosted media URLs and edit instructions to the VAP API. This creates a genuine data exposure boundary because user-supplied media references and transformation requests are transmitted to a remote service, which may process sensitive or private content.

Content

Scanner excerpt · SKILL.md (reported line 143)May include surrounding context.

Create Operation

bash
curl -s -X POST https://api.vapagent.com/api/v1/operations \
  -H "Authorization: Bearer $VAP_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"operation":"background_remove","media_url":"https://example.com/photo.png"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The operation endpoint sends externally hosted media URLs and edit instructions to the VAP API. This creates a genuine data exposure boundary because user-supplied media references and transformation requests are transmitted to a remote service, which may process sensitive or private content.

Content

Scanner excerpt · SKILL.md (reported line 143)May include surrounding context.

Create Operation

bash
curl -s -X POST https://api.vapagent.com/api/v1/operations \
  -H "Authorization: Bearer $VAP_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"operation":"background_remove","media_url":"https://example.com/photo.png"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

Polling the operation endpoint sends authenticated requests and operation identifiers to the external VAP service. This is a legitimate external transmission pathway and may expose workflow metadata or media-processing activity to the third-party provider.

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

Poll Operation

bash
curl -s https://api.vapagent.com/api/v1/operations/OPERATION_ID \
  -H "Authorization: Bearer $VAP_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This example repeats the same external transmission pattern: prompts and the bearer token are sent to a remote API. While expected for this integration, it still represents a true security-relevant behavior because the skill enables outbound data flow to an external provider.

Content

Scanner excerpt · SKILL.md (reported line 202)May include surrounding context.

Image

bash
curl -s -X POST https://api.vapagent.com/api/v1/generations \
  -H "Authorization: Bearer $VAP_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"kind":"image","prompt":"A fluffy orange tabby cat on a sunlit windowsill, soft bokeh, golden hour light, photorealistic","params":{"aspect_ratio":"16:9"}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This example repeats the same external transmission pattern: prompts and the bearer token are sent to a remote API. While expected for this integration, it still represents a true security-relevant behavior because the skill enables outbound data flow to an external provider.

Content

Scanner excerpt · SKILL.md (reported line 202)May include surrounding context.

Image

bash
curl -s -X POST https://api.vapagent.com/api/v1/generations \
  -H "Authorization: Bearer $VAP_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"kind":"image","prompt":"A fluffy orange tabby cat on a sunlit windowsill, soft bokeh, golden hour light, photorealistic","params":{"aspect_ratio":"16:9"}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The poll example demonstrates another authenticated request to the external generation endpoint. Even as sample documentation, it promotes repeated outbound transmission of authorization data and task metadata to a third-party API, which is security-relevant in agent environments.

Content

Scanner excerpt · SKILL.md (reported line 207)May include surrounding context.

-H "Content-Type: application/json"
-d '{"kind":"image","prompt":"A fluffy orange tabby cat on a sunlit windowsill, soft bokeh, golden hour light, photorealistic","params":{"aspect_ratio":"16:9"}}'

curl -s https://api.vapagent.com/api/v1/generations/GENERATION_ID
-H "Authorization: Bearer $VAP_API_KEY"

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The video generation example transmits user prompts and an authorization token to the external VAP API. Because prompts may contain sensitive business or personal content, this is a real confidentiality concern even though such transmission is central to the skill's purpose.

Content

Scanner excerpt · SKILL.md (reported line 214)May include surrounding context.

Video

bash
curl -s -X POST https://api.vapagent.com/api/v1/generations \
  -H "Authorization: Bearer $VAP_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"kind":"video","prompt":"Drone shot over misty mountains at sunrise","params":{"duration":8,"aspect_ratio":"9:16","resolution":"1080p"}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The music generation example also sends prompts and credentials to a remote service. As with other examples, it constitutes genuine external transmission and could expose proprietary or sensitive creative instructions outside the local system.

Content

Scanner excerpt · SKILL.md (reported line 223)May include surrounding context.

Music

bash
curl -s -X POST https://api.vapagent.com/api/v1/generations \
  -H "Authorization: Bearer $VAP_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"kind":"music","prompt":"Upbeat lo-fi hip hop beat, warm vinyl crackle, chill vibes","params":{"duration":120,"instrumental":true,"audio_format":"wav","loudness_preset":"streaming"}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The AI edit example sends a media URL plus editing prompt to the external operations API. If the media URL points to private content or includes signed access tokens, the skill could inadvertently disclose sensitive assets to the external provider.

Content

Scanner excerpt · SKILL.md (reported line 232)May include surrounding context.

AI Edit

bash
curl -s -X POST https://api.vapagent.com/api/v1/operations \
  -H "Authorization: Bearer $VAP_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"operation":"ai_edit","media_url":"https://example.com/photo.jpg","prompt":"Change the background to a sunset beach"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The upscale example references external media and transmits it through the operations workflow to a third-party API. This is a real exposure point for user content and activity metadata, even if it is expected product behavior.

Content

Scanner excerpt · SKILL.md (reported line 241)May include surrounding context.

Upscale

bash
curl -s -X POST https://api.vapagent.com/api/v1/operations \
  -H "Authorization: Bearer $VAP_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"operation":"upscale","media_url":"https://example.com/photo.jpg","options":{"scale":4}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The background removal example shares a user media URL with the external VAP API. This creates a legitimate confidentiality and privacy risk if the image is sensitive or the URL grants privileged access to private storage.

Content

Scanner excerpt · SKILL.md (reported line 250)May include surrounding context.

Background Remove

bash
curl -s -X POST https://api.vapagent.com/api/v1/operations \
  -H "Authorization: Bearer $VAP_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"operation":"background_remove","media_url":"https://example.com/photo.jpg"}'

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:268