Back to skill

Security audit

Venice Ai

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does what it says, but it can fetch arbitrary URLs and upload local or fetched media to Venice AI without strong scoping, size limits, or consent checks.

Review before installing in shared, enterprise, or agent-autonomous environments. Use it only with data you are willing to send to Venice AI and any model/search providers involved. Avoid passing internal URLs, localhost addresses, cloud metadata URLs, private files, secrets, or untrusted prompts that will be rendered in generated HTML. Prefer sandboxing or network egress rules if URL inputs remain enabled.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/venice.py:437
Finding

Unrestricted Audio URL Fetching Enables SSRF and Resource Exhaustion

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/venice-upscale.py:114
Finding

Image Upscaling URL Input Enables SSRF, Internal-Content Upload, and Memory Exhaustion

Content
View full analysis
str: """Download an HTTP(S) URL and return as raw base64 string.""" req = urllib.request.Request(url, headers={"User-Agent": USER_AGENT}) with urllib.request.urlopen(req, timeout=60) as resp: data = resp.read() return base64.b64encode(data).decode("ascii") def upscale_image_from_url( api_key: str, image_url: str, scale: int = 2, enhance: bool = False, enhance_prompt: str | None = None, enhance_creativity: float | None = None, replication: float | None = None, ) -> bytes: """ Upscale an image via Venice API using a URL or base64 data URL. HTTP(S) URLs are downloaded and converted to base64 first. Returns raw image bytes. """ # API requires base64, not HTTP URLs if image_url.startswith(("http://", "https://")): image_url = _fetch_url_as_base64(image_url) elif image_url.startswith("data:"): # Extract base64 from data URL if ";base64," in image_url: image_url = image_url.split(";base64,", 1)[1] url = f"{API_BASE}/image/upscale" payload: dict = { "image": image_url, "scale": scale, "enhance": enhance, } ``` ### Technical Analysis The upscale command locally retrieves any URL beginning with `http://` or `https://`. Checking only the textual scheme does not prevent access to internal destinations. The implementation does not inspect the destination address, control redirects, restrict ports, validate response media, or impose a response-size limit. Consequently, the process can be induced to access internal network services using its own network privileges. After retrieval, the complete response is Base64 ...[truncated 1663 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/venice-image.py:181
Finding

Unescaped Image Prompts Permit Stored HTML Injection in Generated Galleries

Content
View full analysis
None: """Generate HTML thumbnail gallery.""" thumbs = "\n".join( f""" {it['prompt'][:100]}{'...' if len(it['prompt']) > 100 else ''} """ for it in items ) html = f""" Venice Image Gallery :root {{ color-scheme: dark; }} body {{ margin: 24px; font: 14px/1.4 ui-sans-serif, system-ui; background: #0b0f14; color: #e8edf2; }} h1 {{ font-size: 18px; margin: 0 0 16px; }} .grid {{ display: grid; grid-template-columns: repeat(auto-fill, minmax(280px, 1fr)); gap: 16px; }} figure {{ margin: 0; padding: 12px; border: 1px solid #1e2a36; border-radius: 14px; background: #0f1620; }} img {{ width: 100%; height: auto; border-radius: 10px; display: block; }} figcaption {{ margin-top: 10px; color: #b7c2cc; font-size: 13px; }} code {{ color: #9cd1ff; }}

Venice Image Gallery

Output: {out_dir.as_posix()}

{thumbs}
""" (out_dir / "index.html").write_text(html, encoding="utf-8") ``` ### Technical Analysis The image prompt is user-controlled and is inserted directly into an HTML document without escaping. The output directory and generated filename values are also interpolated into HTML contexts without contextual encoding. Truncating the prompt to 100 characters does not prevent injection. A short payload can close the `` element and introduce new HTML elements with active attributes. The injected content is persisted in `index.html` and executes when a user opens the generated gallery. The practical capabilities ...[truncated 1385 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (43)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code chunk is narrowly focused on image editing via Venice AI and does not implement the broad set of platform features described. Its primary purpose is a CLI utility for single-image and multi-image edit operations, including file/URL handling and writing output images. While 'AI editing' is accurately represented, the description materially overstates the skill's capabilities by claiming many unrelated functions not present in this code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description substantially overstates the capabilities represented by this code chunk. The script is narrowly focused on Venice image APIs: image generation, style/model listing, optional web-search-assisted image generation, and background removal. It does not implement the broad multi-modal platform described, including text, audio, embeddings, social search, video, music, upscaling, or general AI editing. While over-declaration alone is not always problematic, here the declared primary purpose ('complete Venice AI platform') is materially broader than the actual behavior of this specific code chunk, so this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description presents the skill as an all-in-one Venice AI platform spanning many modalities and services. However, the actual code only implements music generation against Venice AI audio endpoints, plus related support actions like quoting, polling, downloading, metadata saving, model listing, and cleanup. There is no evidence in this chunk of the other declared capabilities. This is a material description-to-behavior mismatch because the declared primary purpose is much broader than what the code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This code chunk's primary purpose is much narrower than the declared description. The description claims a full Venice AI platform with numerous modalities and services, while the actual code only handles one feature: image upscaling. That is a material description-to-behavior mismatch because the supplied code does not substantiate the broad declared capability set. The URL download behavior is supportive of the upscaling feature rather than a separate major capability, but it does show external resource access limited to fetching an input image and calling the Venice API. No evidence is present here for text generation, search, speech, video, music, editing, or other listed functions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description advertises a broad, all-in-one Venice AI platform with numerous multimodal and search capabilities. The supplied code chunk is narrowly focused on Venice video operations only. It interacts exclusively with video-related API endpoints (/video/quote, /video/queue, /video/retrieve, /video/complete), handles local/remote media inputs, and saves generated MP4 output. There is no evidence in this chunk of text, search, embedding, audio transcription/synthesis, image generation/editing, background removal, upscaling, or music-generation functionality. While video creation is one capability mentioned in the description, the declared purpose materially overstates what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description substantially overstates the implemented functionality. The code does support several declared capabilities: text/chat generation, image analysis, embeddings, TTS, speech-to-text, model browsing, and it exposes flags for web search and X/Twitter search within chat requests. However, there is no code for image generation, background removal, video creation, music generation, upscaling, or AI editing. The primary purpose is a Venice AI CLI for a subset of platform APIs, not the full platform described. No concerning undeclared capabilities are present beyond normal auth/config reading and HTTP access needed to call the API.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

md
| `venice-video.py` | Video generation (Sora, WAN, Runway) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 640)May include surrounding context.

md
| `venice-video.py` | Video generation (Sora, WAN, Runway) |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
87% confidence
Finding

Documenting a --no-validate option can allow requests to bypass model or parameter validation, which weakens safety checks and may enable unexpected downstream behavior or accidental routing to unsupported endpoints. In a skill that already has broad networked capabilities, encouraging validation bypass increases the chance of misuse and makes auditing harder.

Content

Scanner excerpt · SKILL.md (reported line 658)May include surrounding context.

md
|---------|----------|
| `VENICE_API_KEY not set` | Set env var or configure in `~/.clawdbot/clawdbot.json` |
| `Invalid API key` | Verify at [venice.ai/settings/api](https://venice.ai/settings/api) |
| `Model not found` | Run `--list-models` to see available; use `--no-validate` for new models |
| Rate limited | Check `--show-usage` output |
| Video stuck | Videos can take 1-5 min; use `--timeout 600` for long ones |
| Vision not working | Ensure you're using a vision-capable model (e.g., `qwen3-vl-235b-a22b`) |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/venice-image.py (reported line 294)May include surrounding context.

python
ap.add_argument("--resolution", help="Resolution preset (1K, 2K, 4K)")
    ap.add_argument("--aspect-ratio", help="Aspect ratio (1:1, 16:9, etc.)")
    ap.add_argument("--safe-mode", action="store_true", default=False, help="Blur adult content (default: false)")
    ap.add_argument("--no-safe-mode", action="store_false", dest="safe_mode", help="Disable safe mode")
    ap.add_argument("--hide-watermark", action="store_true", help="Remove Venice watermark")
    ap.add_argument("--embed-exif", action="store_true", help="Embed prompt info in image EXIF metadata")
    ap.add_argument("--lora-strength", type=int, help="LoRA strength 0-100 for applicable models")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/venice-image.py (reported line 303)May include surrounding context.

python
ap.add_argument("--complete", metavar="QUEUE_ID", help="Clean up a previously downloaded video (use with --model)")
    ap.add_argument("--list-models", action="store_true", help="List available video models and exit")
    ap.add_argument("--quote", action="store_true", help="Show price estimate and exit (no generation)")
    ap.add_argument("--no-validate", action="store_true", help="Skip model validation")
    args = ap.parse_args()

    api_key = require_api_key()

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/venice-video.py (reported line 251)May include surrounding context.

python
ap.add_argument("--complete", metavar="QUEUE_ID", help="Clean up a previously downloaded video (use with --model)")
    ap.add_argument("--list-models", action="store_true", help="List available video models and exit")
    ap.add_argument("--quote", action="store_true", help="Show price estimate and exit (no generation)")
    ap.add_argument("--no-validate", action="store_true", help="Skip model validation")
    args = ap.parse_args()

    api_key = require_api_key()

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/venice.py (reported line 23)May include surrounding context.

python
def get_api_key() -> str | None:
    """
    Get API key from multiple sources in order:
    1. VENICE_API_KEY environment variable
    2. ~/.clawdbot/clawdbot.json at skills.entries.venice-ai.env.VENICE_API_KEY
       (also checks venice-ai-media for backward compatibility)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/venice_common.py (reported line 19)May include surrounding context.

python
def get_api_key() -> str | None:
    """
    Get API key from multiple sources in order:
    1. VENICE_API_KEY environment variable
    2. ~/.clawdbot/clawdbot.json at skills.entries.venice-ai.env.VENICE_API_KEY
       (also checks venice-ai-media for backward compatibility)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises and documents capabilities that require environment access, file I/O, and network access, but it does not declare an explicit tool scope such as permissions or allowed-tools. This creates an over-broad execution surface where an agent may invoke the skill without clear boundaries, increasing the chance of unintended data access or exfiltration through third-party API calls.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The metadata and framing present the skill as a general-purpose solution for nearly any AI task, without narrow activation boundaries or exclusions. In agent environments, vague scope encourages over-invocation and may cause sensitive prompts, files, or URLs to be sent to this external service when a more limited local tool would be safer.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README repeatedly markets the skill as a complete platform for many unrelated tasks, but does not specify concrete triggers, guardrails, or conditions for safe use. That makes accidental misuse more likely, especially in autonomous agents that select skills based on broad descriptions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation emphasizes privacy but does not clearly and consistently warn that prompts, uploaded files, fetched URLs, web searches, and X/Twitter searches may transit third-party infrastructure depending on the selected feature or model. This can mislead users into sending sensitive material under a false assumption of universal privacy, especially where Grok/X search or remote scraping are involved.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
### Get Your API Key

1. Create account at [venice.ai](https://venice.ai)
2. Go to [venice.ai/settings/api](https://venice.ai/settings/api)
3. Click "Create API Key" → copy the key (starts with `vn_...`)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation explicitly describes an option to scrape URLs found in user messages, which can cause user-provided content or referenced resources to be fetched and transmitted to an external service without a clear privacy warning or consent flow. In an agent skill context, this increases the risk of unintended data disclosure, SSRF-like behavior against internal URLs provided by users, or fetching sensitive intranet resources if downstream safeguards are weak.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The top-level docstring says "Generate images via Venice AI Image API," and the main argument parser description repeats that framing, yet the code includes a --background-remove mode that edits an existing image instead of generating one. This is an active documentation-to-code contradiction about the script's actual function.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and CLI description present this script as a tool to generate images via the Venice AI Image API, but it also exposes a separate background-removal workflow. Background removal is a different image-editing capability, so the documented purpose of this file does not fully match the behavior implemented in code.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

This endpoint can receive either remote URLs or uploaded local image content for background removal, creating a real data-transfer risk if users assume processing is local. In a skill ecosystem, tools may be invoked on user files automatically, so undisclosed outbound transmission of image contents can expose sensitive personal or internal data.

Content

Scanner excerpt · scripts/venice-image.py (reported line 216)May include surrounding context.

python
Accepts local file path, HTTP URL, or data URL.
    Returns PNG bytes with transparent background.
    """
    url = "https://api.venice.ai/api/v1/image/background-remove"

    if image_src.startswith(("http://", "https://")):
        # JSON payload with URL

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

When given a local file, the script reads the image bytes and uploads them to a remote Venice API endpoint, but the user-facing interface does not clearly warn that local content will leave the machine. In an agent-skill context, this can cause unintended exfiltration of sensitive images if the tool is invoked on private files under the assumption it works locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script transparently converts local image, video, or audio files into data URLs and later submits them to the remote Venice API, but it does not provide an explicit warning or consent checkpoint before transmitting local content off-host. In a CLI handling potentially sensitive media, this creates a real privacy and data-exfiltration risk, especially because users may not realize that supplying a local path results in full file upload to a third-party service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.