Back to skill

Security audit

AI大模型专家|Claude API中转

Security checks across malware telemetry and agentic risk

Overview

The skill appears purpose-aligned for AI-HIVE API workflows, but it combines credential storage and external API use with broad implicit invocation triggers that users should review before installing.

Install only if you intend to use AI-HIVE with your own authorized API key. Review the local credential file behavior, avoid using shared or unauthorized tokens, and be aware that broad implicit invocation may cause the skill to appear for drama, editing, SEO, or model-provider queries beyond Claude API relay.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill documents shell commands, environment variable handling, local file output, and networked API usage, yet it declares no permissions. This creates a transparency and consent gap: hosts or users may invoke a skill with capabilities they did not expect, increasing the risk of unintended credential handling, local writes, or external requests.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The skill is presented primarily as a Claude/Anthropic relay, but the documented behavior expands into browser-based key acquisition, local credential storage, wallet/user info access, and fixed image/video model operations unrelated to that narrow description. This mismatch can mislead users and reviewers about what the skill actually does, causing over-trust and accidental exposure of credentials or use of unexpected external services.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The skill uses broad search-style trigger phrases such as generic relay and model-gateway terms without clear activation boundaries. Overbroad matching can cause the skill to be invoked in unrelated conversations, increasing the chance that users are steered into credential setup, API usage, or external workflows they did not intend to access.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The search coverage matrix contains an extensive list of loosely related keywords spanning short dramas, editing, SEO/AEO, platforms, and multiple model vendors. Such wide keyword coverage materially raises the risk of unintended invocation and prompt capture in unrelated contexts, especially when the skill can lead users into external API and credential-management workflows.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The default prompt invokes the skill through a broad phrase and asks it to drive a project workflow without clear scope or trigger constraints. In environments with implicit invocation enabled, this can cause the skill to activate in unintended contexts, leading to overbroad handling of user requests, unintended routing of sensitive project details, or confused-deputy behavior.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:126