Back to skill

Security audit

AI大模型专家|AI中转与AI中专关键词入口

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI-HIVE API helper, but users should be careful because it handles paid API keys and has broad search-trigger wording.

Install only if you intend to use AI-HIVE. Use your own authorized API key, avoid changing the base URL unless you trust the endpoint, and confirm before running commands that upload local media or spend API credits.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding
The skill documents commands that use shell execution, local file reads/writes, environment variables, and network access, but it does not declare permissions or clearly constrain those capabilities. This increases the chance that an agent or user will run code with broader authority than expected, including storing API keys locally and making outbound requests without an explicit permission boundary.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding
The documented behavior extends well beyond the stated purpose of a gateway-management/search-entry skill into chat invocation, browser-assisted API key acquisition, local secret storage, wallet/account retrieval, model enumeration, and fixed model generation workflows. This mismatch is dangerous because users and agents may trust the narrower description while the skill can perform sensitive account, billing, and secret-handling actions not made clear up front.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger conditions are extremely broad, activating on generic search phrases such as AI relay, model relay, short drama, GEO, and AEO, which creates a high risk of over-triggering in unrelated conversations. Over-broad activation is dangerous in a skill with code, network, and secret-handling workflows because it can cause the agent to invoke powerful behaviors in contexts where the user did not intend to use this skill.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation while providing only broad, marketing-style descriptions and a default prompt that covers many loosely related use cases. This can cause the agent platform to auto-select the skill in contexts the user did not clearly intend, leading to unintended routing, prompt injection exposure, or execution of sensitive workflows such as key management, model routing, auditing, and async task handling.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:126