Back to skill

Security audit

AI大模型专家|海外短剧多语言本地化与发行

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI-HIVE workflow for short-drama planning plus user-directed image/video generation, with API-key setup and media uploads that fit its stated purpose.

Install only if you intend to use AI-HIVE for this workflow. Expect prompts and any media paths you provide to be sent to AI-HIVE, and treat the locally stored API key as a real credential that should be protected, rotated, and removed when no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The implementation materially diverges from the declared skill purpose: instead of a drama-localization/planning assistant, it provides a broad AI Hive client for chat, model enumeration, account inspection, media upload, image/video generation, polling, and downloading. Capability mismatch is dangerous because users and reviewers may grant trust and permissions based on the manifest while the code exercises a much wider operational scope, increasing the chance of unauthorized data handling or misuse.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
Exposing a user-info endpoint allows the skill to retrieve account details and wallet/balance information unrelated to the stated drama-localization purpose. Even if the API is legitimate, this expands access to sensitive account metadata and can surprise users who did not consent to financial/account inspection from this skill context.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The model-listing capability enables discovery of the full set of available backend models, which exceeds the declared specialized purpose and broadens the skill into a general platform exploration tool. This increases attack surface and can facilitate misuse of unintended models or hidden capabilities under the cover of a narrowly described skill.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The module docstring explicitly describes a 'general AI capability invocation tool,' contradicting the specialized manifest and confirming that the file is intentionally broader than advertised. Such hidden generality undermines review boundaries and trust assumptions, making it easier to smuggle expansive capabilities into a seemingly narrow skill.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill enables implicit invocation, but the manifest does not provide a narrowly scoped trigger or usage boundary. This increases the chance the agent will auto-select the skill in loosely related conversations, causing unintended disclosure of user context or unrequested execution of the skill’s workflow.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:128