Back to skill

Security audit

广告素材失败诊断|AI-HIVE

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI-HIVE workflow for diagnosing and rebuilding ad creatives, with expected but user-controlled API, media upload, and local video-processing behavior.

Install only if you intend to use AI-HIVE for ad creative diagnosis and optional media generation. Review prompts and routing before any paid generation, use only media you are authorized to upload, and avoid storing or pasting real API keys into logs, screenshots, or shared workspaces.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill documents executable capabilities that can access environment variables, local files, the network, and the shell, but it does not declare corresponding permissions or boundaries. This creates hidden authority: a caller may invoke code paths that handle API keys, upload local media, or run ffmpeg/subprocess operations without an explicit permission contract, increasing the risk of unintended data exposure or unsafe execution.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The manifest presents the skill as a diagnosis tool, but the documented behavior expands into generic chat, image/video generation, uploads, downloads, and standalone media processing. This mismatch is dangerous because users and orchestrators may grant trust or invoke the skill under a narrow diagnostic use case while it actually supports much broader content production and external data transfer operations.

Description-Behavior Mismatch

Medium
Confidence
84% confidence
Finding
The workflow markets itself as failure diagnosis but explicitly includes structure extraction, originality transformation, new script creation, and prompt generation. In context, this increases the chance of scope creep from analysis into content adaptation and production, which can trigger copyright, compliance, and data-sharing risks beyond what a user may expect from a diagnostic skill.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The runnable examples demonstrate end-to-end video generation, API-key usage, task polling, downloading results, and ffmpeg-based media editing. These operational steps materially exceed a passive diagnosis function and expose users to billing, data exfiltration, and local file-processing risks if they assume the skill is only analytical.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The file is presented as an ad-creative failure diagnosis skill, but the implementation is a broadly capable AI-Hive upload/chat/image/video generation CLI. That capability mismatch is dangerous because it expands what an invoking agent can do beyond the user's apparent intent, enabling unrelated content generation and media handling under a misleading skill label.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The code exposes generic chat and image-generation commands that are unrelated to ad-failure diagnosis. In an agent environment, this broadens the attack surface and can let downstream workflows invoke unreviewed capabilities for arbitrary generation tasks, defeating least-privilege expectations created by the skill description.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The module docstring explicitly describes a generic AI capability tool, which contradicts the declared diagnosis-only skill context. This inconsistency increases the chance that operators and automated systems trust the skill for a narrow purpose while it actually enables much broader actions, leading to misuse and policy bypass.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt and broad skill framing make invocation criteria too loose, so the skill may activate for a wide range of adjacent ad/marketing requests without clear user intent. In an agent system, over-broad activation can cause unintended execution paths, unexpected external API usage, or the generation of operational marketing workflows when the user only wanted analysis or discussion.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The default prompt hard-codes Chinese output ('production-ready Chinese workflow') without indicating that this is user-selectable or required by platform constraints. This can override user preferences, reduce transparency, and increase the chance of misunderstandings in workflow execution or review, especially when code, API commands, or safety-relevant instructions are expected in another language.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.