Back to skill

Security audit

AI大模型专家|AI漫剧剪辑

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed AI-HIVE comic-drama editing helper that uses user-provided media and API credentials, with no evidence of hidden exfiltration or destructive behavior.

Install only if you are comfortable giving AI-HIVE access to the media files you explicitly upload and storing an AI-HIVE API key locally. Use authorized assets, review generated commands before running them, and avoid placing real API keys in public repositories or shared screenshots.

Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill advertises and demonstrates access to environment variables, local files, shell commands, and networked API calls, but it does not declare any permissions or capability boundaries. This makes it harder for users and hosting systems to understand the true trust surface, increasing the risk of unexpected file access, command execution, or secret exposure during use.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The documented purpose is narrow video/comic-drama editing, but the skill apparently includes broader capabilities such as generic chat, image generation/editing, wallet/user-info lookup, model enumeration, browser-based API-key setup, and arbitrary media upload. This mismatch is dangerous because users may grant trust or provide sensitive assets expecting only editing behavior, while the skill can perform materially broader actions including data exfiltration to third-party services and local credential handling.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:131