Back to skill

Security audit

AI大模型专家|短剧人物版人物板

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed AI-HIVE image/video workflow with user-controlled uploads and local API-key setup, though its image wrapper is inconsistently branded for a generic GPT Image 2 image workflow.

Install only if you are comfortable using AI-HIVE for remote image/video generation, uploading selected reference files to that service, and storing an API key locally. Review the image wrapper mismatch before relying on it for a strictly character-board-only workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The skill is presented as a narrowly scoped short-drama character-board workflow, but the described scripts expose broader generic AI-HIVE functions including account initialization, model enumeration, media upload, arbitrary chat, and general image/video generation wrappers. This scope mismatch can mislead users into granting trust or credentials to a tool that effectively acts as a general-purpose API client, increasing the chance of unauthorized or unexpected actions, cost exposure, or data handling beyond user expectations.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The file presents itself as a generic AI capability wrapper for chat, image, video, model discovery, upload, and polling, which materially exceeds the declared drama-character-board purpose. In a skill ecosystem, this kind of scope drift increases the attack surface and enables operators or downstream users to invoke unrelated capabilities that were not reviewed or expected for this skill.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The embedded fixed configuration hardwires a GPT Image 2 product-image generation skill, not a drama character board skill. This mismatch is dangerous because reviewers and users may trust the manifested purpose while the actual executable path routes prompts and assets to a different model/workflow, undermining policy review, consent, and least-privilege expectations.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The generic text chat endpoint is unrelated to a narrowly scoped drama-character-board image skill and gives the skill a broader arbitrary-content generation channel than advertised. In context, this increases misuse potential and weakens review assumptions because a supposedly image-focused skill can also send free-form text prompts and media to a general chat model.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The module and CLI descriptions explicitly market the tool as a generic AI capability client, contradicting the narrower manifested skill identity. Misleading capability descriptions are dangerous in plugin/skill review pipelines because they obscure the true behavior of the artifact and can cause reviewers to approve functionality they did not intend to permit.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The file exposes broad capabilities beyond the advertised skill purpose, including arbitrary chat, model enumeration, account inspection, upload, and generic image/video generation. In an agent-skill ecosystem, this capability mismatch weakens least-privilege expectations and can let a caller invoke networked operations or inspect account state that users and reviewers would not expect from a character-board tool.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The embedded skill configuration targets short-drama video generation, which materially contradicts the manifest describing a character-board tool. This kind of hidden retargeting is dangerous because downstream systems may grant or recommend the skill based on benign metadata while the actual implementation performs a different, broader operation with more data transfer and generation capability.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The module presents itself as a generic AI capability tool, while the wrapper markets it as a dedicated video skill. This inconsistency is a security concern because reviewers and users may assess trust and permissions based on the wrapper branding, while the underlying code retains a much broader operational surface than expected.

Missing User Warnings

Medium
Confidence
79% confidence
Finding
The skill uploads arbitrary local files and downloads generated artifacts over the network without explicit, in-flow notice about remote transfer, third-party storage, or retention. In this skill context, users may provide sensitive media, drafts, or proprietary assets, so silent transmission increases privacy and data-handling risk even if the destination service is legitimate.

Missing User Warnings

Low
Confidence
72% confidence
Finding
The init flow automatically opens a browser to a remote URL containing a skill-identifying query parameter, which discloses attribution metadata without prior warning. While low severity, this still creates an unexpected outbound request and can reveal usage context or telemetry about the invoked skill.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:128