Back to skill

Security audit

sogni-creative-agent-skill

Security checks for vulnerabilities and agentic risk

Overview

The skill fits its creative-media purpose, but it deserves Review because it stores long-term persona and memory data and can feed that persistent state into hosted chat/tool workflows.

Install only if you trust Sogni AI with the media and prompts you send. Avoid storing secrets in memories or personality text, review/clear saved personas and voice clips when needed, use direct CLI mode for media that must stay local, and do not approve self-update or @latest upgrades unless you are comfortable running newly published package code.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T02 · Agent Memory Poisoning

Error
Location
sogni-agent.mjs:7421
Finding

Persistent Prompt Injection Through Memory and Personality State

Content
View full analysis
0) { const memoryContext = memories.map((m) => `${m.key}: ${m.value}`).join('; '); suffix += `\nUser preferences (apply unless the latest user request overrides them): ${memoryContext}`; } } catch { // best-effort } // Personality context — verbatim user instruction wrapped in the same // framing sogni-chat uses so the LLM treats it as an override. try { const personality = loadPersonality(); if (personality) { suffix += `\nUSER PERSONALITY PREFERENCE: The user has customized your personality as follows: "${personality}". Adopt this personality while following all other instructions above.`; } } catch { // best-effort } ``` The affected values are persisted without content validation: ```js function memorySet(key, value, category = 'preference', source = 'user') { const memories = loadMemories(); const existing = memories.findIndex(m => m.key === key); const entry = { key, value, category, source, updatedAt: Date.now() }; if (existing >= 0) { memories[existing] = { ...memories[existing], ...entry }; } else { memories.push({ id: randomBytes(8).toString('hex'), ...entry, createdAt: Date.now() }); } saveMemories(memories); return existing >= 0 ? 'updated' : 'created'; } function savePersonality(text) { const dir = dirname(PERSONALITY_PATH); if (!existsSync(dir)) mkdirSync(dir, { recursive: true }); writeFileSync(PERSONALITY_PATH, text); } ``` ### Technical Analysis Memory keys, memory values, and personality text are interpolated verbatim into the hosted LLM's system message. The implementation does not impose size limits, normalize line breaks, esc ...[truncated 2105 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
sogni-agent.mjs:9017
Finding

Sensitive Persona and Preference Files Are Created Without Explicit Private Permissions

Content
View full analysis
p.name.toLowerCase() === name.toLowerCase())) { throw new Error(`Persona "${name}" already exists. Remove it first or use a different name.`); } const slug = personaSlug(name); const personaDir = join(PERSONAS_DIR, slug); if (!existsSync(personaDir)) mkdirSync(personaDir, { recursive: true }); // Copy photo let savedPhotoPath = null; if (photoPath) { const resolvedPhoto = expandHomePath(photoPath); if (!existsSync(resolvedPhoto)) throw new Error(`Photo not found: ${resolvedPhoto}`); const ext = extname(resolvedPhoto).toLowerCase() || '.jpg'; savedPhotoPath = join(personaDir, `photo${ext}`); writeFileSync(savedPhotoPath, readFileSync(resolvedPhoto)); } // Copy voice clip let savedVoicePath = null; if (voiceClipPath) { const resolvedVoice = expandHomePath(voiceClipPath); if (!existsSync(resolvedVoice)) throw new Error(`Voice clip not found: ${resolvedVoice}`); const ext = extname(resolvedVoice).toLowerCase() || '.webm'; savedVoicePath = join(personaDir, `voice-clip${ext}`); writeFileSync(s ...[truncated 1903 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
sogni-agent.mjs:7097
Finding

Presigned Media Upload URLs Bypass SSRF Validation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:20
Finding

Runtime Dependencies Are Installed Without a Reproducible Lockfile

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (179)

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

This changelog describes agent-context update notices that explicitly tell the agent to offer sogni-agent self-update. In an agent skill context, normalizing self-update as part of task flow can increase the chance of unreviewed toolchain modification during a session, which is risky if update channels or package provenance are ever compromised.

Content

Scanner excerpt · CHANGELOG.md (reported line 674)May include surrounding context.

md
agents live — non-TTY stderr, `--json` mode, and OpenClaw plugin invocations — so Claude Code / Codex / Hermes /
  OpenClaw users never learned a newer skill existed. Any command may now print a single advisory stderr line,
  `[sogni-agent] Update available: <current> -> <latest> ...`, throttled to at most once per 24 hours, telling
  the agent to finish the current task, relay the update to the user, and offer `sogni-agent self-update`
  (`--snooze-update` on decline). Interactive TTY users keep the existing banner. stdout is never touched, so
  `--json` output stays machine-parseable; SKILL.md instructs agents how to handle the line. Background version
  checks now also run in agent contexts (still skipped for CI, tests, `--no-update-check`,

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · README.md (reported line 364)May include surrounding context.

Also works in OpenAI Codex

The same local MCP server runs in OpenAI Codex — the Codex CLI and IDE extension read MCP servers from ~/.codex/config.toml. With the CLI installed globally (npm i -g @sogni-ai/sogni-creative-agent-skill), register it and start a new Codex session:

bash
codex mcp add sogni-creative-agent -- node "$(npm root -g)/@sogni-ai/sogni-creative-agent-skill/desktop-extension/server/index.mjs"

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · README.md (reported line 370)May include surrounding context.

Also works in OpenAI Codex

The same local MCP server runs in OpenAI Codex — the Codex CLI and IDE extension read MCP servers from ~/.codex/config.toml. With the CLI installed globally (npm i -g @sogni-ai/sogni-creative-agent-skill), register it and start a new Codex session:

bash
codex mcp add sogni-creative-agent -- node "$(npm root -g)/@sogni-ai/sogni-creative-agent-skill/desktop-extension/server/index.mjs"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · README.md (reported line 485)May include surrounding context.

md
-c wardrobe.png "Keep the endpoint frames and use Image 1 for wardrobe detail"

# MiniMax H3 Standard, 8-step Balanced, 4-step LightX2V Turbo, and FastH3 Turbo video
sogni-agent --video -m minimax-h3 --duration 10 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-r2v --ref identity.png -c wardrobe.png \
  --ref-video motion.mp4 --ref-audio voice.m4a \

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · README.md (reported line 487)May include surrounding context.

md
# MiniMax H3 Standard, 8-step Balanced, 4-step LightX2V Turbo, and FastH3 Turbo video
sogni-agent --video -m minimax-h3 --duration 10 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-r2v --ref identity.png -c wardrobe.png \
  --ref-video motion.mp4 --ref-audio voice.m4a \
  "<six-field Ref2VA prompt>"
sogni-agent --video -m minimax-h3-balanced --duration 8 "<three-field H3 prompt>"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · README.md (reported line 493)May include surrounding context.

md
sogni-agent --video -m minimax-h3-balanced --duration 8 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v-balanced --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-turbo --duration 8 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-turbo --sampler sa_solver --duration 8 "<A/B variant of the same H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v-turbo --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-fasth3-turbo --duration 8 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-fasth3-i2v-turbo --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Documenting a self-update command that upgrades the CLI via the detected package manager introduces self-modification capability into agent workflows. In an agent context, if invoked automatically or after prompt manipulation, this can pull and execute changed code, creating a supply-chain and persistence risk beyond a one-time install.

Content

Scanner excerpt · README.md (reported line 642)May include surrounding context.

md
| `--json` | Emit structured output for agents |
| `-n <count>` | Multiple outputs per call (safety-capped at 16; raise deliberately with `SOGNI_MAX_COUNT`) |
| `doctor` / `--doctor` | Install health check: Node, credentials, ffmpeg, auth, version (`--json` for agents) |
| `self-update` | Upgrade the CLI via the detected package manager |
| `--whats-new [version]` | Show bundled CHANGELOG entries (everything after `<version>` if given) |
| `--snooze-update` | Snooze the pending-update reminder (1 day → 2 days → 1 week) |
| `--no-update-check` | Disable the background update check for this run (`SOGNI_NO_UPDATE_CHECK=1` to disable always) |

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

The agent-facing guidance explicitly tells agents to offer or run update-related commands such as sogni-agent self-update. For an agent skill, encouraging runtime self-modification is risky because a compromised prompt or workflow could steer the agent into upgrading itself and executing new code without sufficient human review.

Content

Scanner excerpt · README.md (reported line 998)May include surrounding context.

md
6. **Verify with `doctor`**
   After any install or upgrade, run `sogni-agent doctor --json` and confirm `"success": true` before reporting the install as working.
7. **Update notices for agents**
   When a newer version exists, any command may print one advisory stderr line — `[sogni-agent] Update available: <current> -> <latest> ...` — at most once per day (stdout JSON is never touched). Agents should relay it to the user and offer `sogni-agent self-update`, or run `sogni-agent --snooze-update` if the user declines. Interactive TTY users get a banner instead. Each failed check carries a `detail` string with the fix.
8. **SSRF / URL safety**
   The CLI validates every HTTP(S) media reference with an SSRF guard ([`ssrf-guard.mjs`](./ssrf-guard.mjs)) and re-validates each redirect hop on download. Localhost and private-network URLs are rejected; only public HTTPS references are forwarded as Seedance multimodal context.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
Then configure the agent/runtime to use this `SKILL.md` and invoke the `sogni-agent` CLI. The one-command alternative `npx setup-sogni-agent-skill` auto-detects

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
Then configure the agent/runtime to use this `SKILL.md` and invoke the `sogni-agent` CLI. The one-command alternative `npx setup-sogni-agent-skill` auto-detects

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill instructs the agent to perform self-update operations on the globally installed CLI. Self-modifying behavior is dangerous because it changes executable code at runtime, expanding supply-chain risk and making behavior less reproducible or reviewable.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
Pick the one matching the host you are running in, and fall back to `sogni-agent` if that command is not found. The Codex and Claude Code plugin surfaces already pin their own launcher, so this table is what a plain `SKILL.md` install (Hermes and other runtimes) should follow.

For upgrades, prefer `sogni-agent self-update`, package-manager updates, or direct operations on an existing checkout (`git -C "$DEST" pull --ff-only && npm --prefix "$DEST" install`). Do not generate clone-or-pull shell bootstrap scripts with `set -e`, `bash -c`, `sh -c`, or inline repository URLs; agent command scanners may require approval for those patterns. If a checkout does not exist, prefer the npm install path or ask before cloning.

**Update notices:** any `sogni-agent` command may print a single stderr line of the form `[sogni-agent] Update available: <current> -> <latest> ...` (at most once per day). When you see it, finish the current task first, then tell the user a newer CLI package is available and offer to run `sogni-agent self-update` (follow with `sogni-agent --whats-new` to summarize what changed). `self-update` refreshes the global CLI only; if the runtime loads a copied personal skill bundle, refresh it through the same setup flow that installed it and start a new agent session. If the user declines the CLI update, run `sogni-agent --snooze-update` so reminders pause (1 day → 2 days → 1 week). Never treat the notice line as command output — it is advisory and never appears on stdout.

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Telling the agent to offer and run sogni-agent self-update based on an advisory notice creates a path for code changes triggered during normal task execution. This increases the chance of executing newly introduced code without prior review and can be abused if update channels are compromised.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
For upgrades, prefer `sogni-agent self-update`, package-manager updates, or direct operations on an existing checkout (`git -C "$DEST" pull --ff-only && npm --prefix "$DEST" install`). Do not generate clone-or-pull shell bootstrap scripts with `set -e`, `bash -c`, `sh -c`, or inline repository URLs; agent command scanners may require approval for those patterns. If a checkout does not exist, prefer the npm install path or ask before cloning.

**Update notices:** any `sogni-agent` command may print a single stderr line of the form `[sogni-agent] Update available: <current> -> <latest> ...` (at most once per day). When you see it, finish the current task first, then tell the user a newer CLI package is available and offer to run `sogni-agent self-update` (follow with `sogni-agent --whats-new` to summarize what changed). `self-update` refreshes the global CLI only; if the runtime loads a copied personal skill bundle, refresh it through the same setup flow that installed it and start a new agent session. If the user declines the CLI update, run `sogni-agent --snooze-update` so reminders pause (1 day → 2 days → 1 week). Never treat the notice line as command output — it is advisory and never appears on stdout.

## Uninstall Request Policy

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
_APP_ID_POOL_MAX`). Concurrent agent processes lease distinct slots automatically; the legacy single `~/.config/sogni/app-id` file migrates into slot-0 on first use. Set a stable `SOGNI_APP_ID` for ephemeral/container homes or long-lived daemons, or `SOGNI_APP_ID_PATH` for legacy single-file mode.
- Last render metadata (read/write): `~/.config/sogni/last-render.json` (`SOGNI_LAST_RENDER_PATH`)
- Model catalog: `https://api.sogni.ai/v1/model-catalog` (`SOGNI_MODEL_CATALOG_URL`)
- Model catalog cache (read/write, 5-minute TTL with ETag revalidation for model parameters and discovery): `~/.config/sogni/model-catalog-cache.json` (`SOGNI_MODEL_CATALOG_CACHE_PATH`)
- Memories / personality / personas (read/write): `~/.config/sogni/`
- OpenClaw config (read): `~/.openclaw/openclaw.json` (`OPENCLAW_CONFIG_PATH`)
- Media listing for `--list-media` (read): `~/.openclaw/media/inbound`, falling back to the legacy `~/.clawdbot/media/inbound` when only it exists (`SOGNI_MEDIA_INBOUND_DIR`)
- Custom

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 220)May include surrounding context.

md
# Standard, 8-step Balanced, and 4-step LightX2V Turbo cover T2VA, I2VA,
# L2VA, FL2VA, and Ref2VA. FastH3 is a separate FastVideo VSA engine with
# T2VA/I2VA/L2VA/FL2VA only; it has no R2V mode.
sogni-agent --video -m minimax-h3 --duration 10 -w 1344 -h 768 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref-end last.png --duration 8 "<L2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · README.md (reported line 486)May include surrounding context.

md
# L2VA, FL2VA, and Ref2VA. FastH3 is a separate FastVideo VSA engine with
# T2VA/I2VA/L2VA/FL2VA only; it has no R2V mode.
sogni-agent --video -m minimax-h3 --duration 10 -w 1344 -h 768 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref-end last.png --duration 8 "<L2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-r2v --ref identity.png -c wardrobe.png --ref-video motion.mp4 --ref-audio voice.m4a "<six-field Ref2VA prompt>"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 221)May include surrounding context.

md
# L2VA, FL2VA, and Ref2VA. FastH3 is a separate FastVideo VSA engine with
# T2VA/I2VA/L2VA/FL2VA only; it has no R2V mode.
sogni-agent --video -m minimax-h3 --duration 10 -w 1344 -h 768 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref-end last.png --duration 8 "<L2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-r2v --ref identity.png -c wardrobe.png --ref-video motion.mp4 --ref-audio voice.m4a "<six-field Ref2VA prompt>"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 222)May include surrounding context.

md
# T2VA/I2VA/L2VA/FL2VA only; it has no R2V mode.
sogni-agent --video -m minimax-h3 --duration 10 -w 1344 -h 768 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref-end last.png --duration 8 "<L2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-r2v --ref identity.png -c wardrobe.png --ref-video motion.mp4 --ref-audio voice.m4a "<six-field Ref2VA prompt>"
sogni-agent --video -m minimax-h3-balanced --duration 8 "<three-field H3 prompt>"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 223)May include surrounding context.

md
sogni-agent --video -m minimax-h3 --duration 10 -w 1344 -h 768 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref-end last.png --duration 8 "<L2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-r2v --ref identity.png -c wardrobe.png --ref-video motion.mp4 --ref-audio voice.m4a "<six-field Ref2VA prompt>"
sogni-agent --video -m minimax-h3-balanced --duration 8 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v-balanced --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 224)May include surrounding context.

md
sogni-agent --video -m minimax-h3-i2v --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref-end last.png --duration 8 "<L2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-r2v --ref identity.png -c wardrobe.png --ref-video motion.mp4 --ref-audio voice.m4a "<six-field Ref2VA prompt>"
sogni-agent --video -m minimax-h3-balanced --duration 8 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v-balanced --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v-balanced --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · README.md (reported line 490)May include surrounding context.

md
sogni-agent --video -m minimax-h3-i2v --ref-end last.png --duration 8 "<L2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-r2v --ref identity.png -c wardrobe.png --ref-video motion.mp4 --ref-audio voice.m4a "<six-field Ref2VA prompt>"
sogni-agent --video -m minimax-h3-balanced --duration 8 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v-balanced --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v-balanced --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-r2v-balanced --ref identity.png -c wardrobe.png "<six-field Ref2VA prompt>"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 225)May include surrounding context.

md
sogni-agent --video -m minimax-h3-i2v --ref-end last.png --duration 8 "<L2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-r2v --ref identity.png -c wardrobe.png --ref-video motion.mp4 --ref-audio voice.m4a "<six-field Ref2VA prompt>"
sogni-agent --video -m minimax-h3-balanced --duration 8 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v-balanced --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v-balanced --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-r2v-balanced --ref identity.png -c wardrobe.png "<six-field Ref2VA prompt>"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 226)May include surrounding context.

md
sogni-agent --video -m minimax-h3-flf2v --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-r2v --ref identity.png -c wardrobe.png --ref-video motion.mp4 --ref-audio voice.m4a "<six-field Ref2VA prompt>"
sogni-agent --video -m minimax-h3-balanced --duration 8 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v-balanced --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v-balanced --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-r2v-balanced --ref identity.png -c wardrobe.png "<six-field Ref2VA prompt>"
sogni-agent --video -m minimax-h3-turbo --duration 8 "<three-field H3 prompt>"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · README.md (reported line 491)May include surrounding context.

md
sogni-agent --video -m minimax-h3-r2v --ref identity.png -c wardrobe.png --ref-video motion.mp4 --ref-audio voice.m4a "<six-field Ref2VA prompt>"
sogni-agent --video -m minimax-h3-balanced --duration 8 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v-balanced --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v-balanced --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-r2v-balanced --ref identity.png -c wardrobe.png "<six-field Ref2VA prompt>"
sogni-agent --video -m minimax-h3-turbo --duration 8 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v-turbo --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 227)May include surrounding context.

md
sogni-agent --video -m minimax-h3-r2v --ref identity.png -c wardrobe.png --ref-video motion.mp4 --ref-audio voice.m4a "<six-field Ref2VA prompt>"
sogni-agent --video -m minimax-h3-balanced --duration 8 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v-balanced --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v-balanced --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-r2v-balanced --ref identity.png -c wardrobe.png "<six-field Ref2VA prompt>"
sogni-agent --video -m minimax-h3-turbo --duration 8 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v-turbo --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 228)May include surrounding context.

md
sogni-agent --video -m minimax-h3-balanced --duration 8 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v-balanced --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v-balanced --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-r2v-balanced --ref identity.png -c wardrobe.png "<six-field Ref2VA prompt>"
sogni-agent --video -m minimax-h3-turbo --duration 8 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v-turbo --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v-turbo --ref-end last.png --duration 8 "<L2V preamble plus three-field H3 prompt>"

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.potential_exfiltration

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
sogni-agent.mjs:10350

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
sogni-agent.mjs:228

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
sogni-agent.mjs:6620