Back to skill

Security audit

AI大模型专家|短剧角色一致性

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed AI-HIVE image/video workflow that uses a local API key and user-selected uploads, with no evidence of hidden, destructive, or exfiltrating behavior.

Install this only if you intend to use AI-HIVE for media generation and are comfortable storing an AI-HIVE API key locally, uploading selected reference media, and potentially incurring generation costs. Review prompts, model choices, routing mode, and output paths before running generation commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The skill is presented as a narrowly scoped 'short-drama character consistency' assistant, but its documented behavior extends into broad AI-HIVE account initialization, model/routing selection, wallet/user queries, generic chat, media upload, and generic image/video generation. This scope expansion can mislead users about what the skill will do and what data or account resources it may access, increasing the risk of unintended API usage, data exposure, or surprise billing.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The embedded SKILL_CONFIG hard-codes this skill as a generic GPT Image 2 image-generation tool, which materially contradicts the advertised 'drama character consistency' purpose. This mismatch can cause users or higher-level agents to invoke capabilities they did not intend, weakening trust boundaries and enabling unauthorized or out-of-scope content generation under misleading packaging.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The file is presented and marketed as a narrow short-drama/character-consistency skill, but the implementation exposes a much broader AI-Hive client surface including arbitrary chat, model discovery, uploads, and general generation workflows. This creates a scope-mismatch vulnerability because consumers, reviewers, or policy gates may grant trust and permissions appropriate for a specialized media skill while actually enabling a generic API wrapper.

Context-Inappropriate Capability

Low
Confidence
88% confidence
Finding
The skill includes a user-info operation that can retrieve account/profile and wallet data unrelated to character-consistency generation. In a skill ecosystem, exposing extra account-inspection functionality increases unnecessary data access and broadens the blast radius if the skill is invoked by an agent or user who expected only media generation behavior.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The unrestricted chat endpoint allows arbitrary text and multimodal interactions beyond the stated visual/video character-consistency role. That turns the skill into a general-purpose LLM proxy, which can bypass product scoping, policy expectations, and review assumptions associated with a narrowly described media workflow.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The top-level docstring explicitly describes the tool as a generic AI capability caller, which directly conflicts with the skill's specialized manifest and marketing. This inconsistency is dangerous in a plugin/agent environment because trust, approval, and invocation decisions may rely on manifest intent while the code exposes substantially broader capabilities.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill can be invoked implicitly and its description/default prompt are broad enough to match many requests about drama, characters, images, or video workflows without clear boundaries. This increases the chance of over-triggering, causing the agent to activate unexpectedly and steer user interactions or downstream media-generation actions outside the user's explicit intent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:128