Security audit
flux
Security checks for vulnerabilities and agentic risk
Overview
This skill is a coherent RunAPI Flux image-generation helper with disclosed API-key use, network calls, and paid task submission controls.
Install this only if you are comfortable using RunAPI for Flux image work. Treat prompts and any local input images as data sent to the service, keep the API key protected, and remember that successful submissions may create billable tasks even though the skill includes controls to avoid duplicate paid requests.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
