Back to skill

Security audit

propzapi-full

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims: it sends user-requested image, template, and screenshot jobs to PropzAPI using the user's API key.

Install only if you intend to use PropzAPI as a third-party rendering service. Avoid sending confidential page URLs, private HTML, or sensitive template variables unless you are comfortable processing that data through PropzAPI, and monitor credit usage because render and screenshot calls consume credits.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares access to environment secrets and network communication but does not define any explicit tool scope such as allowed tools or permissions. That weakens least-privilege controls and makes it harder for a host to constrain where secrets may be used or what outbound actions the skill is permitted to perform.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The screenshot function sends the provided URL to the propzapi service via _post, which is a network operation involving user or system data. Although the function docstring explains what it does, it does not explicitly warn that the URL will be sent to a third-party external service, so there is no clear disclosure of the data-sharing aspect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The create_template function posts user-provided HTML, dimensions, and variables to the remote propzapi service. The docstring describes the feature but does not clearly warn that potentially sensitive template contents are uploaded to a third-party service, which is a safety-relevant disclosure omission for network transmission of user data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
@patch("handler.urllib.request.urlopen")
    def test_embed_url_posts_v1_embed_url(self, mock_urlopen):
        mock_urlopen.return_value = _mock_response(b'{"url": "https://api.propzapi.com/r/signed"}')
        with patch.dict(os.environ, {"PROPZAPI_KEY": "test_key"}):
            handler.embed_url(template="tpl_abc", modifications={"title": "Hi"})
        req = _req(mock_urlopen)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

md
@patch("handler.urllib.request.urlopen")
    def test_embed_url_posts_v1_embed_url(self, mock_urlopen):
        mock_urlopen.return_value = _mock_response(b'{"url": "https://api.propzapi.com/r/signed"}')
        with patch.dict(os.environ, {"PROPZAPI_KEY": "test_key"}):
            handler.embed_url(template="tpl_abc", modifications={"title": "Hi"})
        req = _req(mock_urlopen)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tests/test_handler.py (reported line 127)May include surrounding context.

python
@patch("handler.urllib.request.urlopen")
    def test_embed_url_posts_v1_embed_url(self, mock_urlopen):
        mock_urlopen.return_value = _mock_response(b'{"url": "https://api.propzapi.com/r/signed"}')
        with patch.dict(os.environ, {"PROPZAPI_KEY": "test_key"}):
            handler.embed_url(template="tpl_abc", modifications={"title": "Hi"})
        req = _req(mock_urlopen)

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

L073 states that the base URL is hardcoded so the key never reaches any other host. However, L079 documents obtaining a key with POST /v1/register, implying an additional API interaction path not covered by the narrow claim. This is a documentation-level contradiction about network scope, even though it may be benign.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This code file exercises HTTP requests to external PropzAPI endpoints and includes access to the PROPZAPI_KEY credential, but there is no user-facing warning, confirmation, or explanatory comment about transmitting request data to a third-party service. For SQP-2 on code files, network calls that transmit user or system data and access to sensitive credentials should have some visible disclosure unless clearly covered elsewhere.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.