Back to skill

Security audit

AI大模型专家|短剧漫剧一站式制片厂

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed AI-HIVE video-production workflow with no hidden installer, persistence, or unrelated data access, but users should confirm rights and costs before generation.

Before installing, understand that this skill is meant to coordinate AI-HIVE media generation and may involve uploading creative assets or reference material to that service. Confirm you have rights to any people, voices, music, trademarks, products, novels, or videos used, and approve paid generation only after reviewing model, price, and deliverable details.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill’s activation criteria are broad and cover many common media-production tasks, which can cause the agent to invoke this skill in situations where a narrower or safer specialized skill would be more appropriate. Overbroad routing increases the chance of unintended tool use, unnecessary exposure of user content to external services, and mistaken initiation of planning for paid or rights-sensitive generation workflows.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill exposes a very broad default prompt and description that authorize the agent to 'plan and execute' an end-to-end production workflow without clear trigger boundaries, scope limits, or approval gates. In agent systems, ambiguous activation language can cause overreach into unintended actions, tool usage, or processing of sensitive user-provided materials, especially when the skill is designed to orchestrate multiple generation steps and model selections.

Static analysis

No suspicious patterns detected.