Back to skill

Security audit

AI大模型专家|霸总短剧 AI生成与编辑

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed AI-HIVE image and video generation skill that uses your API key and selected media, with no hidden destructive or background behavior found.

Install only if you are comfortable giving AI-HIVE an API key and uploading the specific images, videos, audio, prompts, and reference materials you choose. Confirm expected cost before submitting generation tasks, keep the key out of public files, and review any command before it uploads local media or starts a billable job.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill documents executable shell commands and references scripts that use environment variables, local files, network access, and writable state, yet it declares no permissions. This creates a transparency and consent problem: a user or host may invoke a skill believing it is content-only while it can read local paths, persist configuration, and send data to external services.

Tp4

High
Category
MCP Tool Poisoning
Confidence
84% confidence
Finding
The documented purpose is a narrowly scoped short-drama generation skill, but the referenced behavior appears broader, including chat, image input handling, account/balance queries, model enumeration, browser-based key setup, and unrelated image generation/editing capabilities. Capability creep and undocumented features increase the attack surface and can lead users to expose credentials, private media, or account data to functions they did not reasonably expect.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The file presents itself as a specialized short-drama video skill, but bundles a broad generic AI Hive client with unrelated capabilities such as account inspection, model enumeration, text chat, image generation, media upload, and arbitrary API access patterns. This violates least privilege and increases the reachable attack surface: any caller who trusts this as a narrow video tool may unknowingly grant credentials to a much broader API wrapper.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The skill can call a user-info endpoint that likely returns account metadata and wallet balance, which is unrelated to the declared short-drama generation purpose. In a skill setting, unnecessary access to account data creates avoidable privacy and reconnaissance risk if the skill is invoked with a valid API key.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
A generic text-chat API is exposed even though the skill is marketed as a short-drama video generator. This expands the skill beyond its declared function and could be used to send arbitrary prompts and uploaded media to external models, creating data exfiltration and misuse risk under a misleading trust boundary.

Context-Inappropriate Capability

Low
Confidence
82% confidence
Finding
Standalone image generation is broader than the declared video-focused purpose and increases the operational scope of the skill. While lower risk than account access, it still weakens least-privilege assumptions and can cause users to disclose prompts or reference images to an external service under a misleading skill identity.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:127