Back to skill

Security audit

1688 电商视频生成与编辑

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI Hive video-generation helper, with ordinary credential setup and media upload behavior for that purpose.

Install only if you are comfortable sending the selected product images, factory videos, audio, prompts, and generated task data to AI Hive and with storing an AI Hive API key locally. Use a dedicated API key if possible, avoid passing unrelated or sensitive files to --upload/--image/--video/--audio, and monitor any generation costs or credits in your AI Hive account.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill exposes shell, filesystem, environment, and network-capable execution patterns in SKILL.md but does not declare permissions or capability boundaries. This is dangerous because operators and policy layers cannot accurately assess what the skill can access, enabling unexpected data access, outbound requests, or command execution if the referenced script is broader than the stated video workflow.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The declared purpose is a narrow 1688 video-generation/editing workflow, but the implementation reportedly supports much broader AI Hive/OpenAPI actions including chat, image generation, model discovery, media upload, user/wallet queries, and interactive API-key/browser setup. This mismatch is dangerous because it hides materially broader powers than users would expect, increasing the chance of unauthorized account actions, data exposure, cost abuse, or repurposing as a general API tool.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The file presents itself as a generic AI Hive client that supports text chat, image generation, model enumeration, uploads, and account-related operations, which is materially broader than the declared 1688 video-generation/editing purpose. Overbroad capabilities increase attack surface and can let an invoking agent use this skill for unrelated actions the user did not intend, defeating least-privilege expectations for a narrowly scoped skill.

Context-Inappropriate Capability

Low
Confidence
88% confidence
Finding
The user-info capability retrieves account information and wallet/balance data that is unrelated to producing 1688 product videos. Even if read-only, exposing account metadata broadens access beyond user expectations and may leak sensitive commercial or billing information to an agent workflow that only needed media generation.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The chat endpoint allows arbitrary text/multimodal interaction with remote models, which is unrelated to the stated video-editing scope. In an agent setting this creates a covert general-purpose model access path that can be used to process additional user data or perform tasks outside the approved skill boundary.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
Standalone image generation is broader than the advertised video-only workflow and creates another unrelated capability path. This can be abused by an agent to perform non-video content generation, undermining user trust in the skill's declared purpose and expanding what data/prompts are sent to the vendor.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The upload flow sends arbitrary local files to a remote API/object store without an explicit privacy warning or confirmation at the point of transfer. In an agent-driven environment, users may not realize local media is being exfiltrated off-device, especially because upload URLs and storage backends are dynamically provided by the service.

VirusTotal

48/48 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.