Back to skill

Security audit

AI大模型专家|Amazon 亚马逊 电商图片生成与编辑

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly an AI-HIVE image-generation helper, but its broad automatic invocation and external upload/job submission behavior deserve user review before installation.

Install only if you are comfortable with AI-HIVE receiving your prompts and any reference images you provide, and with the skill submitting generation jobs using your API key. Prefer explicit invocation, review costs before batch use, and do not provide private, licensed, or sensitive media unless you intend to upload it to AI-HIVE.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill advertises substantial capabilities such as environment access, file read/write, network access, and shell execution, but does not declare permissions or boundaries for them. This reduces transparency and prevents users or hosting platforms from making informed trust decisions, increasing the risk of unexpected local file access, credential exposure, or command execution through the helper script.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The documented purpose is narrow image generation/editing, but the skill behavior reportedly includes broader chat, video workflows, user/account inspection, model enumeration, pricing inspection, and interactive browser-based API-key setup. This mismatch can cause users or policy systems to grant trust to a tool that performs materially more sensitive actions than expected, especially around account data and local/browser interaction.

Description-Behavior Mismatch

Medium
Confidence
82% confidence
Finding
The manifest frames the skill as Amazon image generation/editing, but the documentation broadens usage into video generation/editing and audio-assisted workflows. Scope drift increases the chance of unintended activation and of users providing broader media inputs than they expected, which can expand data exposure and operational risk.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The invocation language is very broad and can match generic image, marketing, ecommerce, and AIGC requests well beyond a narrow Amazon image-editing scope. Overbroad triggers can cause the skill to activate in contexts where users did not intend to invoke it, increasing the chance that files, prompts, or API-backed operations are sent to an external service unexpectedly.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The search-intent section enumerates a wide set of platforms, models, and content scenarios without clear opt-in constraints, which effectively turns the skill into a catch-all matcher. In a skill that uploads media, polls jobs, and downloads outputs, unintended invocation can expose user prompts and reference assets to an external provider when a narrower tool should have been selected.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation without any trigger scoping or exclusion conditions, which can cause the agent to auto-select this skill in broader contexts than intended. Because this skill can upload reference images, submit generation jobs, poll status, and download results through an external AI-HIVE service, unintended invocation can lead to unauthorized data transfer, unnecessary cost-incurring actions, and execution on user content without clear user intent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.