Back to skill

Security audit

AI大模型专家|AI电商 Live 图生成|AI-HIVE MCP

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed ecommerce Live Photo workflow guide with limited authority and no executable install or persistence behavior.

Before installing, note that this skill may activate on broad ecommerce terms such as platform names. Use it when you intend to generate Live Photo-style ecommerce assets, and only provide product photos, brand materials, or business context that you are authorized to process through AI-HIVE or any connected tool.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger description is very broad and includes many generic ecommerce, platform, and AIGC-related terms such as 淘宝、京东、抖音、Amazon、Shopify and 电商图片. This can cause the skill to activate for unrelated requests, leading to inappropriate routing to an external service workflow and increasing the chance of mishandling user intent, unauthorized processing of product assets, or disclosure of business context to the wrong skill.

Static analysis

No suspicious patterns detected.