Back to skill

Security audit

Popcorn CLI

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Popcorn CLI integration for media generation and file/folder management, with sensitive API key and upload behavior called out to users.

Install this only in an environment where you trust the Popcorn backend and can protect the local API key file. Treat prompts, uploaded files, task IDs, result URLs, and folder IDs as sensitive, and verify the installed CLI version before relying on the resource and folder commands described by the skill.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.