Back to skill

Security audit

AI大模型专家|短剧BGM智能配乐

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed AI-HIVE media editing and generation helper, but users should notice it uploads selected media to an external service and includes broader image/video helper scripts than the BGM-focused name suggests.

Install only if you are comfortable giving AI-HIVE an API key and uploading selected video, image, or audio assets to its service. Use authorized media, avoid placing real keys in shared repos or screenshots, and review the included image/video helper scripts if you expected a strictly local BGM-only tool.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill advertises and demonstrates capabilities that access environment variables, local files, shell commands, and external network services, but it does not declare permissions or boundaries for those actions. This reduces transparency and weakens user consent and sandboxing expectations, which can enable unexpected data access, command execution, or exfiltration if the scripts are invoked in a permissive runtime.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The skill is presented as a narrowly scoped short-drama BGM/scoring helper, but the documented behavior extends into general media generation, API client operations, browser-based initialization, model enumeration, task querying, and local ffmpeg processing. This mismatch can mislead reviewers and users about the true attack surface, increasing the chance that broad execution, file handling, and network features are trusted or approved under a much narrower label.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The file implements a broad AI client with chat, image, video, upload, model enumeration, account lookup, and task polling, while the skill metadata advertises a narrow short-drama BGM/intelligent scoring capability. This scope mismatch is dangerous because it gives the skill materially more capability than users and reviewers would reasonably expect, enabling misuse under the cover of a benign-seeming skill description.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
Exposing user-info and wallet balance retrieval is outside the stated BGM/scoring purpose and unnecessarily expands access to account data. Even if the API only returns the current user's information, this violates least privilege and may disclose sensitive billing or account metadata through a skill that users do not expect to have such reach.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The generic text chat endpoint allows unrestricted model interaction unrelated to the declared BGM smart-scoring function. In context, this makes the skill a concealed general-purpose AI proxy, which can be abused for unintended tasks and bypass policy, billing, or review expectations tied to the advertised specialization.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The module docstring openly describes a generic AI capability tool, directly contradicting the specialized BGM/scoring skill description. This inconsistency is a strong indicator of deceptive packaging or poor security review, and it increases the risk that powerful hidden capabilities are shipped under an unrelated trust label.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill enables implicit invocation, but the activation description is broad and unconstrained, covering many media-editing and AI-generation tasks without tight trigger boundaries. This can cause the agent to invoke the skill in unintended contexts, expanding exposure to untrusted inputs, unexpected tool usage, or prompt-scope overreach.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:131