Back to skill

Security audit

AI大模型专家|Claude Cowork 桌面智能体|AI-HIVE

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed AI-HIVE planning helper that queries models and writes plan files, with no hidden persistence or destructive behavior found.

Install only if you intend to use AI-HIVE/Cowork workflows. Provide AI_HIVE_API_KEY only from a trusted environment, avoid overriding AI_HIVE_BASE_URL unless you control the endpoint, and confirm any paid, batch, publishing, deletion, or account-access action before it runs.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill references executable commands and operational capabilities that require environment access, filesystem read/write, and network access, but it does not declare permissions or capability boundaries in a machine-enforceable way. This creates a transparency and consent gap: a host system or reviewer may not realize the skill can access local files, API keys, and remote services, increasing the chance of overbroad execution or unsafe integration.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding
The skill advertises broad supervised project orchestration with strict authorization boundaries, pricing-based routing, task tracking, and auditable outputs, but the described implementation reportedly only generates plans/templates and performs remote model-list queries. This mismatch is dangerous because users may rely on promised safeguards and controls that are not actually implemented, leading to unsafe assumptions about authorization, billing protection, and execution behavior when connected to real tools or APIs.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger coverage includes generic terms such as tutorials, APIs, workflows, automation, pricing, and related broad AI topics, which can cause the skill to activate for many ordinary requests outside its narrowly intended use. Overbroad invocation increases the chance that users are steered into external platforms, file-handling workflows, or network actions without specifically asking for this skill.

Static analysis

No suspicious patterns detected.