Back to skill

Security audit

广告创意评分与改稿|AI-HIVE

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI-HIVE ad creative workflow helper with user-directed generation, upload, and local video-editing steps, but users should understand the API key storage and possible paid external calls.

Install only if you intend to use AI-HIVE for ad creative workflows. Expect selected media to be uploaded to AI-HIVE when you run generation or upload commands, and expect the init flow to store an API key locally; confirm prompts, routing mode, model parameters, and possible costs before submitting generation tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Lp3

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding
The skill advertises executable commands and operational workflows that use environment variables, local files, network access, and shell tools, but it does not declare permissions for those capabilities. This creates a transparency and least-privilege problem: users and hosting systems cannot accurately assess what the skill may access or invoke, increasing the chance of unintended data exposure, unauthorized file operations, or unsafe command execution in environments that trust metadata for enforcement.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding
The documented behavior exceeds the declared purpose by including generic chat, image/video generation, task polling, API key setup, and standalone ffmpeg editing workflows that are broader than ad scoring and rewrite assistance. That mismatch is dangerous because reviewers or users may grant trust based on a narrow description while the skill can perform materially different networked and local actions, including potentially billable API calls, local media processing, and configuration handling that expand the attack surface.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The blueprint explicitly emits an artifact named '差异化复刻方案' (differentiated replication plan), which materially conflicts with the skill’s own prohibition on unauthorized replication. In an ad-creative rewriting skill, this can normalize or operationalize imitation workflows and make it easier for downstream agents or users to produce derivative creatives that infringe rights, especially if guardrails are weak elsewhere.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The file advertises itself as a generic AI-Hive media generation tool and exposes broad generation/upload capabilities, while the skill metadata promises ad-creative scoring and rewrite assistance. This mismatch is dangerous because it creates a capability-confusion channel: a user or orchestrator may invoke the skill expecting bounded ad-review behavior, but instead gain a general media generation interface that can be repurposed far beyond the declared scope.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The skill-specific entrypoint only exposes generate/task/upload operations and does not implement the promised scoring, diagnosis, or rewrite outputs. In a tool-routing environment, this can mislead the system into handing sensitive creative assets to a capability that primarily uploads and generates media, increasing the risk of unauthorized content creation or data transfer outside the user's expected workflow.

Context-Inappropriate Capability

Medium
Confidence
83% confidence
Finding
User-info and wallet-balance retrieval exceed the stated need of an ad-scoring/rewrite skill and expose account metadata unrelated to the advertised function. While not inherently malicious, unnecessary account introspection expands the attack surface and can leak billing or identity information if the skill is invoked under false assumptions.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
Generic chat and image generation capabilities are broader than the declared ad-creative scoring/rewrite purpose, enabling arbitrary model use once an API key is configured. In context, this overbreadth is risky because the skill can be used as a general AI proxy rather than a narrowly scoped ad-review assistant, defeating least-privilege expectations.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The module docstring explicitly describes a general-purpose AI capability tool, contradicting the declared ad-creative scoring/rewrite intent. Such contradictions are a strong indicator of deceptive or poorly controlled capability packaging, which can cause unsafe tool routing and misuse of uploaded creative assets.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The manifest allows implicit invocation but does not constrain when the skill should trigger or what conditions must be met first. In a skill that can generate production-ready workflows and runnable AI-HIVE commands, overly broad auto-invocation can cause the agent to apply ad-generation or rewrite behavior in unintended contexts, increasing the chance of unsafe automation, policy bypass, or user-surprising actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.