Back to skill

Security audit

AI大模型专家|校园短剧 AI生成与编辑

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI-HIVE media-generation workflow that handles API keys and user-selected media, with no evidence of hidden or destructive behavior.

Install only if you intend to use AI-HIVE for short-drama media generation. Treat uploaded files and prompts as sent to AI-HIVE, review pricing before generation, and keep the API key private or revoke it if no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding
The skill advertises executable commands that use shell, local files, environment variables, and network access, but the manifest shown does not declare corresponding permissions. This creates a transparency and trust problem: users or hosting platforms may allow execution without understanding the skill can read/write local data, access API keys, and send content to external services.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding
The documented purpose is narrowly framed as campus short-drama generation/editing, but the described tooling appears to support broader AI-HIVE chat, model access, uploads/downloads, credential setup, and unrelated image tooling. This mismatch can mislead users about the true operational scope, causing them to expose credentials, local files, or media to generic remote APIs and broader functionality than expected.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill enables implicit invocation without any visible trigger constraints, which can cause the agent to activate this capability based on broad or ambiguous user requests. Because the skill can influence project planning and generate executable model commands, unintended activation could expose user data or cause unreviewed actions to be proposed in contexts where the user did not explicitly request this specialized workflow.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:127