Security audit
Apidot Flux Kontext Api
Security checks for vulnerabilities and agentic risk
Overview
This is a documentation-only APIDot Flux Kontext helper with no executable code or hidden automation.
Before installing, understand that this skill points agents to APIDot docs and may help design workflows involving API keys, prompts, image URLs, task IDs, and webhooks. Keep APIDOT_API_KEY server-side, avoid logging private prompts or image URLs, and only make live APIDot calls when you intend to use that external service.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
