Back to skill

Security audit

sogni-creative-agent-skill

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Sogni media-generation skill whose sensitive behaviors are expected for its purpose, though users should understand the API key, uploads, billing, persistence, and update flow before installing.

Install this only if you are comfortable giving the Sogni CLI access to your Sogni API key, uploading selected media to Sogni for hosted generation, and potentially incurring provider/token costs. In controlled environments, prefer pinned package versions and review before running self-update; use direct CLI/local modes for media that should not be uploaded.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (213)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · README.md (reported line 369)May include surrounding context.

Also works in OpenAI Codex

The same local MCP server runs in OpenAI Codex — the Codex CLI and IDE extension read MCP servers from ~/.codex/config.toml. With the CLI installed globally (npm i -g @sogni-ai/sogni-creative-agent-skill), register it and start a new Codex session:

bash
codex mcp add sogni-creative-agent -- node "$(npm root -g)/@sogni-ai/sogni-creative-agent-skill/desktop-extension/server/index.mjs"

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · README.md (reported line 375)May include surrounding context.

Also works in OpenAI Codex

The same local MCP server runs in OpenAI Codex — the Codex CLI and IDE extension read MCP servers from ~/.codex/config.toml. With the CLI installed globally (npm i -g @sogni-ai/sogni-creative-agent-skill), register it and start a new Codex session:

bash
codex mcp add sogni-creative-agent -- node "$(npm root -g)/@sogni-ai/sogni-creative-agent-skill/desktop-extension/server/index.mjs"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · README.md (reported line 495)May include surrounding context.

md
-c wardrobe.png "Keep the endpoint frames and use Image 1 for wardrobe detail"

# MiniMax H3 Standard, 8-step Balanced, 4-step LightX2V Turbo, FastH3 Turbo, and FastH3 and Ref2VA Two-Stage (1080p/2K) video
sogni-agent --video -m minimax-h3 --duration 10 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-r2v --ref identity.png -c wardrobe.png \
  --ref-video motion.mp4 --ref-audio voice.m4a \

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · README.md (reported line 497)May include surrounding context.

md
# MiniMax H3 Standard, 8-step Balanced, 4-step LightX2V Turbo, FastH3 Turbo, and FastH3 and Ref2VA Two-Stage (1080p/2K) video
sogni-agent --video -m minimax-h3 --duration 10 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-r2v --ref identity.png -c wardrobe.png \
  --ref-video motion.mp4 --ref-audio voice.m4a \
  "<six-field Ref2VA prompt>"
sogni-agent --video -m minimax-h3-balanced --duration 8 "<three-field H3 prompt>"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · README.md (reported line 503)May include surrounding context.

md
sogni-agent --video -m minimax-h3-balanced --duration 8 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v-balanced --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-turbo --duration 8 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-turbo --sampler sa_solver --duration 8 "<A/B variant of the same H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v-turbo --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-fasth3-turbo --duration 8 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-fasth3-i2v-turbo --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · README.md (reported line 508)May include surrounding context.

md
sogni-agent --video -m minimax-h3-fasth3-turbo --duration 8 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-fasth3-i2v-turbo --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-fasth3-flf2v-turbo --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-fasth3-turbo-2stage --duration 8 "<three-field H3 prompt>"   # 2K: FastH3 Two-Stage, delivered at 2x the canvas
sogni-agent --video -m minimax-h3-fasth3-turbo-2stage --target-resolution 1080 --duration 8 "<three-field H3 prompt>"   # 1080p: 960x544 delivered at 1920x1088
sogni-agent --video -m minimax-h3-r2v-2stage --ref identity.png -c wardrobe.png "<six-field Ref2VA prompt>"   # 2K Ref2VA Two-Stage (20 steps)
sogni-agent --video -m minimax-h3-r2v-balanced-2stage --target-resolution 1080 --ref identity.png "<six-field Ref2VA prompt>"   # 1080p Balanced Ref2VA Two-Stage (8 steps)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · README.md (reported line 509)May include surrounding context.

md
sogni-agent --video -m minimax-h3-fasth3-i2v-turbo --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-fasth3-flf2v-turbo --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-fasth3-turbo-2stage --duration 8 "<three-field H3 prompt>"   # 2K: FastH3 Two-Stage, delivered at 2x the canvas
sogni-agent --video -m minimax-h3-fasth3-turbo-2stage --target-resolution 1080 --duration 8 "<three-field H3 prompt>"   # 1080p: 960x544 delivered at 1920x1088
sogni-agent --video -m minimax-h3-r2v-2stage --ref identity.png -c wardrobe.png "<six-field Ref2VA prompt>"   # 2K Ref2VA Two-Stage (20 steps)
sogni-agent --video -m minimax-h3-r2v-balanced-2stage --target-resolution 1080 --ref identity.png "<six-field Ref2VA prompt>"   # 1080p Balanced Ref2VA Two-Stage (8 steps)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · README.md (reported line 510)May include surrounding context.

md
sogni-agent --video -m minimax-h3-fasth3-flf2v-turbo --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-fasth3-turbo-2stage --duration 8 "<three-field H3 prompt>"   # 2K: FastH3 Two-Stage, delivered at 2x the canvas
sogni-agent --video -m minimax-h3-fasth3-turbo-2stage --target-resolution 1080 --duration 8 "<three-field H3 prompt>"   # 1080p: 960x544 delivered at 1920x1088
sogni-agent --video -m minimax-h3-r2v-2stage --ref identity.png -c wardrobe.png "<six-field Ref2VA prompt>"   # 2K Ref2VA Two-Stage (20 steps)
sogni-agent --video -m minimax-h3-r2v-balanced-2stage --target-resolution 1080 --ref identity.png "<six-field Ref2VA prompt>"   # 1080p Balanced Ref2VA Two-Stage (8 steps)

# MiniMax H3 FastH3 audio-to-video: your voice or song drives the clip and is its soundtrack

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · README.md (reported line 511)May include surrounding context.

md
sogni-agent --video -m minimax-h3-fasth3-turbo-2stage --duration 8 "<three-field H3 prompt>"   # 2K: FastH3 Two-Stage, delivered at 2x the canvas
sogni-agent --video -m minimax-h3-fasth3-turbo-2stage --target-resolution 1080 --duration 8 "<three-field H3 prompt>"   # 1080p: 960x544 delivered at 1920x1088
sogni-agent --video -m minimax-h3-r2v-2stage --ref identity.png -c wardrobe.png "<six-field Ref2VA prompt>"   # 2K Ref2VA Two-Stage (20 steps)
sogni-agent --video -m minimax-h3-r2v-balanced-2stage --target-resolution 1080 --ref identity.png "<six-field Ref2VA prompt>"   # 1080p Balanced Ref2VA Two-Stage (8 steps)

# MiniMax H3 FastH3 audio-to-video: your voice or song drives the clip and is its soundtrack
sogni-agent --video -m minimax-h3-fasth3-ia2v-turbo --ref portrait.png --ref-audio voice.m4a --duration 8 "<I2V preamble plus three-field H3 prompt>"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · README.md (reported line 514)May include surrounding context.

md
sogni-agent --video -m minimax-h3-r2v-balanced-2stage --target-resolution 1080 --ref identity.png "<six-field Ref2VA prompt>"   # 1080p Balanced Ref2VA Two-Stage (8 steps)

# MiniMax H3 FastH3 audio-to-video: your voice or song drives the clip and is its soundtrack
sogni-agent --video -m minimax-h3-fasth3-ia2v-turbo --ref portrait.png --ref-audio voice.m4a --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-fasth3-flfa2v-turbo --ref first.png --ref-end last.png --ref-audio song.mp3 --duration 12 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-fasth3-a2v-turbo --ref-audio song.mp3 --audio-start 30 --duration 15 "<three-field H3 prompt>"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · README.md (reported line 515)May include surrounding context.

md
# MiniMax H3 FastH3 audio-to-video: your voice or song drives the clip and is its soundtrack
sogni-agent --video -m minimax-h3-fasth3-ia2v-turbo --ref portrait.png --ref-audio voice.m4a --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-fasth3-flfa2v-turbo --ref first.png --ref-end last.png --ref-audio song.mp3 --duration 12 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-fasth3-a2v-turbo --ref-audio song.mp3 --audio-start 30 --duration 15 "<three-field H3 prompt>"

# MiniMax H3 keyframes: the clip passes through extra images at chosen times (repeat --keyframe, up to 8)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · README.md (reported line 516)May include surrounding context.

md
# MiniMax H3 FastH3 audio-to-video: your voice or song drives the clip and is its soundtrack
sogni-agent --video -m minimax-h3-fasth3-ia2v-turbo --ref portrait.png --ref-audio voice.m4a --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-fasth3-flfa2v-turbo --ref first.png --ref-end last.png --ref-audio song.mp3 --duration 12 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-fasth3-a2v-turbo --ref-audio song.mp3 --audio-start 30 --duration 15 "<three-field H3 prompt>"

# MiniMax H3 keyframes: the clip passes through extra images at chosen times (repeat --keyframe, up to 8)
sogni-agent --video -m minimax-h3-fasth3-flf2v-turbo --ref first.png --ref-end last.png \

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · README.md (reported line 519)May include surrounding context.

md
sogni-agent --video -m minimax-h3-fasth3-a2v-turbo --ref-audio song.mp3 --audio-start 30 --duration 15 "<three-field H3 prompt>"

# MiniMax H3 keyframes: the clip passes through extra images at chosen times (repeat --keyframe, up to 8)
sogni-agent --video -m minimax-h3-fasth3-flf2v-turbo --ref first.png --ref-end last.png \
  --keyframe turn.png@3.5 --keyframe wave.png@6 --duration 8 \
  "<keyframe alignment line plus three-field H3 prompt that names each keyframe <Picture N> and describes it at its time>"

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

A documented self-update command allows the tool to replace its own code via the package manager. In an agent context, this can let an LLM-triggered workflow modify the installed executable and pull unreviewed newer code, expanding supply-chain and persistence risk.

Content

Scanner excerpt · README.md (reported line 693)May include surrounding context.

md
| `--json` | Emit structured output for agents |
| `-n <count>` | Multiple outputs per call (safety-capped at 16; raise deliberately with `SOGNI_MAX_COUNT`) |
| `doctor` / `--doctor` | Install health check: Node, credentials, ffmpeg, auth, version (`--json` for agents) |
| `self-update` | Upgrade the CLI via the detected package manager |
| `--whats-new [version]` | Show bundled CHANGELOG entries (everything after `<version>` if given) |
| `--snooze-update` | Snooze the pending-update reminder (1 day → 2 days → 1 week) |
| `--no-update-check` | Disable the background update check for this run (`SOGNI_NO_UPDATE_CHECK=1` to disable always) |

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

The agent guidance explicitly suggests agents may offer or run sogni-agent self-update. Because the skill is intended for autonomous runtimes, this creates a real self-modification path where a prompt-triggered action could alter installed code without a full manual review.

Content

Scanner excerpt · README.md (reported line 1056)May include surrounding context.

md
6. **Verify with `doctor`**
   After any install or upgrade, run `sogni-agent doctor --json` and confirm `"success": true` before reporting the install as working.
7. **Update notices for agents**
   When a newer version exists, any command may print one advisory stderr line — `[sogni-agent] Update available: <current> -> <latest> ...` — at most once per day (stdout JSON is never touched). Agents should relay it to the user and offer `sogni-agent self-update`, or run `sogni-agent --snooze-update` if the user declines. Interactive TTY users get a banner instead. Each failed check carries a `detail` string with the fix.
8. **SSRF / URL safety**
   The CLI validates every HTTP(S) media reference with an SSRF guard ([`ssrf-guard.mjs`](./ssrf-guard.mjs)) and re-validates each redirect hop on download. Localhost and private-network URLs are rejected; only public HTTPS references are forwarded as Seedance multimodal context.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
Then configure the agent/runtime to use this `SKILL.md` and invoke the `sogni-agent` CLI. The one-command alternative `npx setup-sogni-agent-skill --version=lat

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
Then configure the agent/runtime to use this `SKILL.md` and invoke the `sogni-agent` CLI. The one-command alternative `npx setup-sogni-agent-skill --version=lat

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
install the CLI above, then run `sogni-agent-goose doctor --json`. The [README](./README.md#goose) also covers the MCP extension.

Self-Modification

High
Category
Rogue Agent
Confidence
93% confidence
Finding

The skill recommends self-updating code (sogni-agent self-update) and package-manager operations from within agent workflows. Allowing an agent-controlled tool to modify its own executable or runtime increases the chance of unreviewed code changes, supply-chain compromise, and persistence of malicious updates.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
Pick the one matching the host you are running in, and fall back to `sogni-agent` if that command is not found. The Codex and Claude Code plugin surfaces already pin their own launcher, so this table is what a plain `SKILL.md` install (Hermes and other runtimes) should follow.

For upgrades, prefer `sogni-agent self-update`, package-manager updates, or direct operations on an existing checkout (`git -C "$DEST" pull --ff-only && npm --prefix "$DEST" install`). Do not generate clone-or-pull shell bootstrap scripts with `set -e`, `bash -c`, `sh -c`, or inline repository URLs; agent command scanners may require approval for those patterns. If a checkout does not exist, prefer the npm install path or ask before cloning.

**Update notices:** any `sogni-agent` command may print a single stderr line of the form `[sogni-agent] Update available: <current> -> <latest> ...` (at most once per day). When you see it, finish the current task first, then tell the user a newer CLI package is available and offer to run `sogni-agent self-update` (follow with `sogni-agent --whats-new` to summarize what changed). `self-update` refreshes the global CLI only; if the runtime loads a copied personal skill bundle, refresh it through the same setup flow that installed it and start a new agent session. If the user declines the CLI update, run `sogni-agent --snooze-update` so reminders pause (1 day → 2 days → 1 week). Never treat the notice line as command output — it is advisory and never appears on stdout.

Self-Modification

High
Category
Rogue Agent
Confidence
93% confidence
Finding

The update-notice flow instructs the agent to offer and run self-update, and even to alter reminder state with --snooze-update. This normalizes self-modification during ordinary use, which is risky because future code can change behavior, permissions, and data handling without stable review.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
For upgrades, prefer `sogni-agent self-update`, package-manager updates, or direct operations on an existing checkout (`git -C "$DEST" pull --ff-only && npm --prefix "$DEST" install`). Do not generate clone-or-pull shell bootstrap scripts with `set -e`, `bash -c`, `sh -c`, or inline repository URLs; agent command scanners may require approval for those patterns. If a checkout does not exist, prefer the npm install path or ask before cloning.

**Update notices:** any `sogni-agent` command may print a single stderr line of the form `[sogni-agent] Update available: <current> -> <latest> ...` (at most once per day). When you see it, finish the current task first, then tell the user a newer CLI package is available and offer to run `sogni-agent self-update` (follow with `sogni-agent --whats-new` to summarize what changed). `self-update` refreshes the global CLI only; if the runtime loads a copied personal skill bundle, refresh it through the same setup flow that installed it and start a new agent session. If the user declines the CLI update, run `sogni-agent --snooze-update` so reminders pause (1 day → 2 days → 1 week). Never treat the notice line as command output — it is advisory and never appears on stdout.

## Uninstall Request Policy

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
_APP_ID_POOL_MAX`). Concurrent agent processes lease distinct slots automatically; the legacy single `~/.config/sogni/app-id` file migrates into slot-0 on first use. Set a stable `SOGNI_APP_ID` for ephemeral/container homes or long-lived daemons, or `SOGNI_APP_ID_PATH` for legacy single-file mode.
- Last render metadata (read/write): `~/.config/sogni/last-render.json` (`SOGNI_LAST_RENDER_PATH`)
- Model catalog: `https://api.sogni.ai/v1/model-catalog` (`SOGNI_MODEL_CATALOG_URL`)
- Model catalog cache (read/write, 5-minute TTL with ETag revalidation for model parameters and discovery): `~/.config/sogni/model-catalog-cache.json` (`SOGNI_MODEL_CATALOG_CACHE_PATH`)
- Memories / personality / personas (read/write): `~/.config/sogni/`
- OpenClaw config (read): `~/.openclaw/openclaw.json` (`OPENCLAW_CONFIG_PATH`)
- Media listing for `--list-media` (read): `~/.openclaw/media/inbound`, falling back to the legacy `~/.clawdbot/media/inbound` when only it exists (`SOGNI_MEDIA_INBOUND_DIR`)
- Custom

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 219)May include surrounding context.

md
# prompt contract — see references/video-prompting.md). Standard, 8-step Balanced, and 4-step
# LightX2V Turbo cover T2VA, I2VA, L2VA, FL2VA, and Ref2VA. FastH3 is a separate FastVideo VSA
# engine with T2VA/I2VA/L2VA/FL2VA only; it has no R2V mode.
sogni-agent --video -m minimax-h3 --duration 10 -w 1344 -h 768 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref-end last.png --duration 8 "<L2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · README.md (reported line 496)May include surrounding context.

md
# LightX2V Turbo cover T2VA, I2VA, L2VA, FL2VA, and Ref2VA. FastH3 is a separate FastVideo VSA
# engine with T2VA/I2VA/L2VA/FL2VA only; it has no R2V mode.
sogni-agent --video -m minimax-h3 --duration 10 -w 1344 -h 768 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref-end last.png --duration 8 "<L2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-r2v --ref identity.png -c wardrobe.png --ref-video motion.mp4 --ref-audio voice.m4a "<six-field Ref2VA prompt>"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 220)May include surrounding context.

md
# LightX2V Turbo cover T2VA, I2VA, L2VA, FL2VA, and Ref2VA. FastH3 is a separate FastVideo VSA
# engine with T2VA/I2VA/L2VA/FL2VA only; it has no R2V mode.
sogni-agent --video -m minimax-h3 --duration 10 -w 1344 -h 768 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref-end last.png --duration 8 "<L2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-r2v --ref identity.png -c wardrobe.png --ref-video motion.mp4 --ref-audio voice.m4a "<six-field Ref2VA prompt>"

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 221)May include surrounding context.

md
# engine with T2VA/I2VA/L2VA/FL2VA only; it has no R2V mode.
sogni-agent --video -m minimax-h3 --duration 10 -w 1344 -h 768 "<three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref first.png --duration 8 "<I2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-i2v --ref-end last.png --duration 8 "<L2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-flf2v --ref first.png --ref-end last.png --duration 8 "<FLF2V preamble plus three-field H3 prompt>"
sogni-agent --video -m minimax-h3-r2v --ref identity.png -c wardrobe.png --ref-video motion.mp4 --ref-audio voice.m4a "<six-field Ref2VA prompt>"
sogni-agent --video -m minimax-h3-balanced --duration 8 "<three-field H3 prompt>"

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.potential_exfiltration

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
sogni-agent.mjs:11490

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
sogni-agent.mjs:249

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
sogni-agent.mjs:7641