Back to skill

Security audit

AI大模型专家|AEO 答案引擎优化

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI-HIVE planning and media-generation helper, but users should be aware it can use an AI-HIVE API key, upload chosen media, and spend API credits when commands are run.

Install only if you intend to use AI-HIVE for planning plus image/video generation. Treat uploaded files and prompts as data sent to an external service, expect API usage to consume account credits, and prefer explicit invocation for generation or upload commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Lp3

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding
The skill documents executable workflows that use shell commands, local files, environment variables, and networked API access, but it does not declare corresponding permissions. This weakens platform trust boundaries because a user or host may invoke a skill believing it is low-privilege when it can actually read local configuration, write outputs, and contact external services.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding
The skill is presented primarily as an AEO/content-planning expert, but the documented behavior extends into a broad AI-HIVE client with model discovery, chat invocation, media generation, and local credential initialization/storage. That mismatch can mislead operators about the true attack surface and data flows, increasing the risk of unintended API use, credential exposure, or execution of higher-risk functionality than expected.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The file implements a broad AI media client with chat, image/video generation, upload, download, and task polling, while the declared skill is an AEO/planning expert. This capability mismatch is dangerous because it grants operators a much wider set of networked actions than users would reasonably expect from the skill metadata, undermining trust boundaries and enabling hidden or accidental use of unrelated functionality.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The ability to query user info and wallet balance is unrelated to the stated AEO expert function and expands access to potentially sensitive account data. In a mismatched skill, this becomes a privacy and reconnaissance concern because a user invoking an AEO assistant would not expect account-inspection operations to be present.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
Generic model enumeration and lookup are broader than the described AEO expert purpose and can reveal backend capabilities that are unnecessary for the advertised workflow. This increases attack surface and enables capability discovery that could be combined with other operations for unintended use.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
Standalone upload and task-management commands enable direct media handling and job control outside the stated expert/planning scope. In context, these functions are hidden operational primitives that materially exceed user expectations and can be used to stage content or retrieve outputs unrelated to the declared skill purpose.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The file implements a generic AI Hive API client for chat, media upload, and image/video generation, which does not match the declared AEO/planning skill purpose. This kind of capability mismatch is dangerous because users may grant trust, credentials, or invoke the skill expecting planning assistance while actually enabling broad external API interaction and media transfer.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The embedded SKILL_CONFIG hardcodes a short-drama video generation workflow unrelated to the advertised AEO expertise. This hidden repurposing increases risk because the effective behavior of the skill is materially different from what operators and users would expect, enabling deceptive invocation of upload/generation features under a mismatched label.

Vague Triggers

Medium
Confidence
77% confidence
Finding
The metadata and summary use very broad search and activation terms spanning AEO, drama creation, ecommerce, search ops, image/video generation, and multiple adjacent domains without clear boundaries. Overbroad triggers raise the chance of accidental invocation in unrelated contexts, which can cause unnecessary access to external APIs, local resources, or workflows the user did not intend to run.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The '搜索覆盖矩阵' contains expansive generic keyword lists across platforms, genres, editing, API routing, and model brands, making the skill eligible for activation in many loosely related conversations. In a skill that also references code execution and external services, broad activation materially increases the risk of unanticipated tool use and user confusion.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill enables implicit invocation without documenting any trigger constraints, which can cause the agent to activate this skill in situations the user did not clearly intend. In a content-generation workflow that can shape planning, prompts, and downstream model usage, ambiguous activation increases the risk of misrouting user requests, unintended data exposure to the skill context, or unauthorized task execution paths.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:133