Back to skill

Security audit

AI大模型专家|短剧封面海报片名Logo

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI-HIVE creative workflow for short-drama images and videos, with user-directed API-key setup, media upload, task polling, and downloads.

Install only if you are comfortable using AI-HIVE with your own API key. Treat uploaded reference images, videos, audio, prompts, task IDs, and generated outputs as provider-visible data, and avoid using unlicensed media or sensitive assets unless you intend to submit them to that service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Lp3

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding
The skill advertises executable shell commands, environment-variable use, local file access, and networked API interaction but does not declare permissions or clearly bound these capabilities. That can mislead users and host systems about the skill’s real authority, increasing the chance of overbroad execution, unintended file/network access, or unsafe credential handling.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
The documented purpose is narrowly framed around short-drama cover/poster/logo generation, but the behavior described is much broader: generic model listing, account/balance queries, chat, arbitrary media upload/download, and credential setup with local storage. This mismatch is dangerous because users may authorize or execute the skill expecting a constrained creative tool while it functions as a general-purpose API client with access to sensitive account, content, and local configuration data.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The skill metadata presents the tool as a short-drama cover/poster/logo assistant, but the code exposes broad video generation, media upload, and task-management capabilities. This scope mismatch can mislead users and reviewers about what the skill can do, increasing the chance of unsafe approval or unintended data/media handling.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The module docstring describes a generic AI capability wrapper covering chat, image generation, video generation, model queries, uploads, and polling, which materially exceeds the stated poster/logo use case. Overbroad hidden capability is dangerous because it defeats least-privilege expectations and makes abuse or accidental misuse easier.

Context-Inappropriate Capability

Low
Confidence
83% confidence
Finding
The code includes a user-info endpoint that can reveal account information and wallet/balance details unrelated to creative asset generation. While not inherently malicious, exposing account-inspection features in a creative skill broadens access to sensitive metadata without a clear need.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill enables implicit invocation with no visible trigger scoping, exclusions, or user-confirmation guardrails. That increases the chance the agent is auto-selected in loosely related contexts, causing unintended execution, prompt injection exposure through user/project content, or accidental use of external model-routing capabilities when the user did not explicitly request this skill.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:128