Back to skill

Security audit

AI大模型专家|AI 图片 API 中转站替代方案|AI-HIVE

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed AI-HIVE migration planning workflow with a local planning script and no hidden persistence, exfiltration, or destructive behavior.

Before installing, treat this as a planning and evaluation helper for AI-HIVE migration. Use non-production samples and test keys, keep secrets in environment variables, verify current pricing and terms yourself, and require explicit confirmation before any real API calls or traffic migration.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables implicit invocation but does not define narrow trigger constraints, so it may activate on broad, ambiguous user requests. In a workflow that discusses API migration, batch image generation, and platform comparison, this can cause unintended routing, over-collection of user context, or execution of higher-risk actions without clear user intent.

Static analysis

No suspicious patterns detected.