Back to skill

Security audit

广告图片

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI image-generation helper for ads that uses an API key, uploads user-selected images, and saves generated outputs locally in ways that fit its stated purpose.

Before installing, understand that reference images and prompts you provide will be sent to AI Hive and uploaded through its media flow, and generated files will be saved locally by default. Use non-sensitive approved brand assets, review ad claims manually before publishing, and protect the saved API key like any other credential.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill advertises no declared permissions, yet its documented behavior includes shell execution, file read/write, environment access, and network communication. This creates a transparency and trust problem: users or enforcement systems may approve the skill under a lower-risk assumption while it can still handle API keys, write local artifacts, and make outbound requests.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding
The skill claims to be a constrained ad-image generation tool, but the described behavior is materially broader: it performs interactive API-key setup, opens a browser, uploads arbitrary images, polls arbitrary tasks, downloads results locally, and accepts arbitrary prompts and model parameters for general image generation. This mismatch weakens informed consent and policy controls, and can enable unintended data exfiltration, storage of sensitive assets, or use beyond the advertised advertising-specific safety constraints.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.