Back to skill

Security audit

AI大模型专家|电商爆款带货视频生成与编辑

Security checks across malware telemetry and agentic risk

Overview

Review before installing: the skill is a coherent AI-HIVE video workflow, but its broad automatic invocation can upload media and submit potentially paid remote jobs without a clear confirmation gate.

Install only if you intend to use AI-HIVE for video generation and are comfortable storing an AI-HIVE API key locally, uploading selected media to the service, and possibly incurring generation charges. Before running it, make sure the agent asks you to confirm any upload or task submission, especially for ambiguous video, ad, or e-commerce requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill documents and operational flow indicate capabilities to read environment/config values, write files, invoke shell commands, and access the network, yet no explicit permissions are declared. This creates a transparency and governance gap: users and the hosting platform may authorize or invoke the skill without understanding that it can handle API keys, upload local media, and persist downloaded outputs. In this context, the undocumented capability set is more dangerous because the skill actively manages credentials and local files, so misuse or overreach could expose secrets or user content.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The documented purpose presents a narrowly scoped e-commerce video generation/editing skill, but the analysis indicates materially broader behavior such as chat, image generation, account/wallet retrieval, and general model catalog access. This scope mismatch undermines informed consent and least privilege, because users may provide credentials and media expecting only video workflows while the skill can touch additional account data and invoke unrelated AI capabilities. The context increases risk because the skill already performs authenticated operations against a real third-party platform.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The invocation language is extremely broad and overlaps with generic AI/video tasks, which can cause the skill to be selected outside its intended narrow use case. Overbroad routing is risky because this skill handles API keys, uploads user-provided media, and submits paid remote jobs; accidental activation can therefore lead to unintended data transfer, cost incurrence, or use of a less-appropriate tool than the user expected. In this context, the broad matching language makes the operational capabilities more dangerous, not less.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The search-intent section claims coverage across a very wide set of tools, platforms, channels, and generic content-production intents without clear boundaries. This can manipulate routing so the skill intercepts broad user requests and then performs authenticated uploads or paid generation tasks under a misleadingly specific brand, increasing the chance of unintended credential use, data disclosure, and cost exposure. Because the skill interfaces with a real external service and stores task/output artifacts, ambiguous activation materially raises risk.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The manifest’s default prompt is broad and action-oriented, instructing the agent to carry out a full AI-HIVE video generation workflow and persist task IDs/results without any explicit user-confirmation gate, scope checks, or exclusion conditions. This increases the chance the skill is invoked in situations where the user did not intend external uploads, task submission, polling, or result downloading, especially because the skill operates on real remote services and user-provided media.

Vague Triggers

High
Confidence
97% confidence
Finding
Enabling implicit invocation without tight contextual constraints creates a real risk that the skill will auto-activate during ordinary conversations about video creation, ecommerce ads, or AIGC content. In this skill’s context, unintended activation is more dangerous because it can cause external service usage, media upload, cost-incurring task execution, and storage of generated outputs or identifiers on a real platform.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.