Back to skill

Security audit

AI大模型API企业网关|AI-HIVE

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed AI-HIVE gateway and media-generation helper, with some broad activation and credential-handling considerations but no hidden or destructive behavior found.

Install only if you intend to use AI-HIVE for gateway design or media generation. Review commands before running them, keep API keys out of logs and repositories, use authorized media only, and confirm pricing/routing before any generation task that may incur charges.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill advertises executable workflows that use environment variables, local file access, shell commands, network calls, and media processing, but it declares no permissions. That mismatch can cause the host or user to invoke the skill without understanding its actual authority, increasing the chance of unintended credential exposure, local file access, or external API actions.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
The skill is presented primarily as a planning and solution-design aid, but the content includes direct operational steps for API invocation, media generation/download, local credential setup, and ffmpeg-based file manipulation. This description-behavior gap is dangerous because users or policy systems may authorize a low-risk advisory skill while it actually performs billable external actions and sensitive local operations.

Vague Triggers

Medium
Confidence
86% confidence
Finding
Using very broad trigger phrases like 'OpenAPI' and 'MCP' can cause the skill to activate in unrelated contexts. Over-broad activation is risky here because the skill contains operational guidance for external API usage, credential setup, and generation workflows, so accidental routing could expose users to unnecessary sensitive actions or confusing instructions.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The usage conditions repeat broad, weakly scoped triggers, making accidental invocation more likely across generic technical discussions. In this skill's context, that raises risk because an incorrectly triggered skill may prompt for API-related setup, file paths, or execution steps outside the user's actual intent.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The manifest allows implicit invocation while describing a broad, natural-language use case, which can cause the skill to be auto-selected in situations the user did not clearly intend. In a skill that can generate production workflows and runnable API commands for external AI gateway operations, over-broad auto-invocation increases the risk of unintended execution planning, misrouting user requests, or exposing sensitive integration guidance in the wrong context.

Static analysis

No suspicious patterns detected.