Back to skill

Security audit

AI大模型专家|Amazon 亚马逊 电商视频生成与编辑

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI-HIVE video workflow that stores an API key locally and uploads chosen media, with no artifact-backed hidden execution or exfiltration.

Install only if you are comfortable giving the skill an AI-HIVE API key and uploading selected media to AI-HIVE. Consider using an environment variable instead of the config file if you do not want persistent local key storage, monitor generation costs, and revoke the key from AI-HIVE if it is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
79% confidence
Finding
The skill is presented as a narrowly scoped Amazon e-commerce video generation/editing tool, but the documented behavior indicates additional account-oriented and broader model-discovery functions, including browser-based API key setup, local secret storage, model catalog enumeration, and user/wallet retrieval. This mismatch weakens informed consent and expands the trust boundary: users may provide credentials or run setup flows without realizing the skill can access broader account data and non-video functionality.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.