Back to skill

Security audit

AI大模型专家|AI电商动图生成|AI-HIVE MCP

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed workflow guide for creating AI-assisted e-commerce product motion images, with no executable installer, hidden persistence, or destructive behavior found.

Installers should use this skill only for authorized product assets and confirm AI-HIVE tools, prices, and rights before generating media. The publisher should narrow the activation description so ordinary marketplace, shopping, or generic image requests do not route into this workflow unintentionally.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill description uses very broad trigger terms such as general e-commerce, image, and platform keywords, which can cause the skill to activate for ordinary product-image or marketplace queries outside its intended scope. Overbroad activation is dangerous because it can route unrelated user requests into a workflow that encourages external tool usage and content-generation actions, increasing the chance of inappropriate execution, confusion, or unintended data handling.

Static analysis

No suspicious patterns detected.