Back to skill

Security audit

AI大模型专家|短剧服装造型设定

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI-HIVE image/video generation workflow for short-drama visual assets, with API-key and media-upload risks users should understand before use.

Install only if you intend to use AI-HIVE for media generation. Treat the API key as a real credential, review any prompts and files before upload, watch for possible generation costs, and consider disabling implicit invocation if you want every external API use to be explicit.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill documents executable workflows that use shell commands, local files, environment variables, and networked API access, but it does not declare those capabilities/permissions explicitly. This weakens user consent and sandbox policy enforcement because consumers may treat the skill as documentation-only while it actually supports credentialed API calls, file I/O, and task/result retrieval.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The described purpose is narrowly framed as short-drama costume/styling planning, but the referenced behavior is much broader: generic AI-HIVE account/model access, chat, image/video generation, uploads/downloads, polling, and local credential setup. This mismatch is dangerous because it can mislead users and reviewers about the actual attack surface, causing them to approve a skill with broader data access and execution pathways than expected.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The file presents itself as a specialized short-drama costume-styling skill, but the implementation exposes a broader generic AI client with text chat, image generation, video generation, model enumeration, uploads, and task polling. That scope mismatch can mislead users and any policy layer that relies on the manifest/description to constrain capability, increasing the chance of unintended data handling or misuse beyond the declared purpose.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The embedded SKILL_CONFIG hardcodes a generic GPT Image 2 image-generation/editing skill, which materially differs from the metadata claiming a drama-costume-styling workflow. This hidden retargeting is more dangerous than a simple description mismatch because operators may believe they are invoking a narrowly scoped domain tool while actually granting access to a general-purpose image editing backend.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The generic text-chat endpoint is unrelated to the advertised specialized image asset workflow, yet it accepts arbitrary prompts and optional uploaded images. In a skill ecosystem that relies on declared purpose for trust and access decisions, this broadens the attack surface and enables unreviewed general-purpose model usage under a misleading domain label.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The file presents itself as a purpose-specific costume-styling skill, but it actually implements a broad AI Hive client exposing generic chat, model discovery, media upload, image generation, and video generation capabilities. This capability mismatch expands what a caller can do beyond the advertised scope, undermining least privilege and increasing the risk of unintended data access, misuse, or policy bypass through a seemingly narrow skill.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The generated skill configuration hardcodes a generic short-drama video skill (`short-drama-video`) with multiple video generation modes, which materially differs from the manifest's costume-styling description. A misleading wrapper around broader generation functions can cause users or orchestrators to authorize a narrower task while actually granting access to more powerful media-generation operations.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill enables implicit invocation without any visible trigger narrowing, domain gating, or confirmation step. That can cause the agent to auto-select this skill in loosely related conversations, increasing the chance of unintended execution, prompt-context leakage into the skill workflow, or user confusion about which tool is acting.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:128