Back to skill

Security audit

Monet AI

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only Monet API integration skill whose external API use is expected, though users should treat prompts, uploads, and verbose curl output as sensitive.

Install only if you intend to use monet.vision with a Monet API key. Treat all prompts, reference images, videos, audio, task metadata, and uploaded files as data sent to a third-party service. Remove the `-v` flag from authenticated curl examples unless you have a controlled way to redact logs, and rotate MONET_API_KEY if verbose authenticated output may have been shared.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:1196
Finding

Bearer API Key May Be Exposed Through Verbose curl Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:1196-1199
Vulnerability Type: Sensitive credential exposure through verbose diagnostic output
Risk Level: Medium

Vulnerable Code

bash
curl -X POST https://monet.vision/api/v1/files \
  -H "Authorization: Bearer $MONET_API_KEY" \
  -F "file=@/path/to/your/file.mp4" \
  -v

Technical Analysis

The documented file-upload command combines an Authorization header containing MONET_API_KEY with curl's verbose (-v) diagnostic mode. Verbose diagnostics can disclose sensitive request details, potentially including authentication headers, depending on the curl version and diagnostic environment.

Because verbose output is written to standard error, the credential may be captured by CI/CD logs, shell-session recordings, AI-agent transcripts, support bundles, or redirected diagnostic files. Although transmitting the key to https://monet.vision is necessary for the declared hosted API functionality, exposing it through local diagnostics is not necessary and exceeds the minimum disclosure required.

The API key itself is loaded from an environment variable rather than hardcoded, which is appropriate. The vulnerability arises from unsafe diagnostic handling rather than from the authentication mechanism.

Attack Path

  1. A user or automation system copies the documented upload command.
  2. The command runs with a valid MONET_API_KEY and verbose mode enabled.
  3. Request diagnostics are displayed or captured by a terminal recorder, CI job, agent transcript, support log, or stderr redirection.
  4. An unauthorized party obtains access to the retained diagnostic output.
  5. If the authorization value was included in that output, the party extracts the bearer token.
  6. The party reuses the token against the Monet API until the credential expires or is revoked.

Impact Assessment

Successful exploitation could grant the attacker the Monet API priv ...[truncated 560 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove -v from the documented upload command:
    bash
    curl -X POST https://monet.vision/api/v1/files \
      -H "Authorization: Bearer $MONET_API_KEY" \
      -F "file=@/path/to/your/file.mp4"
    
  2. If diagnostics are required, use a controlled troubleshooting process that explicitly redacts Authorization, cookies, signed URLs, and other secrets before logs are retained or shared.
  3. Prevent command output containing credentials from being stored in CI logs, agent transcripts, shell history, or support artifacts.
  4. Add documentation warning users not to enable verbose tracing while authenticated unless sensitive fields are safely redacted.
  5. Rotate MONET_API_KEY immediately if verbose output from previous executions may have been recorded or disclosed.
  6. Apply least privilege, usage limits, expiration, and regular rotation to API keys where supported.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This example sends prompts and task parameters, along with an API credential, to an external service. External transmission is expected for an API integration skill, but it is still a real security/privacy concern because user content is leaving the host environment and may include sensitive or regulated information.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

Create a Video Generation Task

bash
curl -X POST https://monet.vision/api/v1/tasks/async \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $MONET_API_KEY" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This API reference again documents outbound transmission of user-supplied content to a third-party endpoint. While core to the skill's functionality, it can still lead to unintended disclosure if an agent forwards sensitive prompts or embedded data without clear user awareness and consent.

Content

Scanner excerpt · SKILL.md (reported line 1071)May include surrounding context.

Request:

bash
curl -X POST https://monet.vision/api/v1/tasks/async \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $MONET_API_KEY" \
  -d '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly instructs users to upload local files to a third-party remote service and only mentions 24-hour retention, without warning that uploaded content may contain sensitive, proprietary, or personal data. In an agent context, this omission is risky because agents may upload user-provided files automatically, causing unintended disclosure outside the local trust boundary.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 1191)May include surrounding context.

md
POST `/api/v1/files` - Upload a file to get an online access URL.

> 📁 **File Storage**: Uploaded files are stored for **24 hours** and will be automatically deleted after expiration.

**Request:**

Static analysis

No suspicious patterns detected.