Back to skill

Security audit

AI大模型专家|牛来大模型全能工作台|AI-HIVE

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed AI-HIVE workflow helper that uses an API key, network model queries, and local plan files, with no hidden persistence or destructive behavior found.

Before installing, understand that this skill may contact AI-HIVE using your API key and may write local plan or task-record JSON files. Keep the API key in environment or credential storage only, review broad implicit activation in the agent settings, and require explicit confirmation before any paid, batch, publishing, deletion, or permission-changing action.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill instructs use of environment variables, local file reads/writes, and network-backed model queries, but no permissions are declared. This creates a transparency and policy-enforcement gap: operators may approve or invoke the skill without understanding that it can access credentials, persist artifacts, and contact external services.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The skill claims identity verification, pricing snapshot checks, routing decisions, task/result persistence, and comparative evaluation, but the described implementation appears to provide only local planning/validation scaffolding. This mismatch is dangerous because users may rely on nonexistent safeguards or verification steps and make procurement, publishing, or automation decisions under false assumptions.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation terms include broad keywords such as AIGC, API, MCP, Agent, workflow, automation, pricing, and marketing-related terms that are common across many unrelated tasks. Overbroad triggers can cause unintended invocation, exposing user prompts, files, or planning context to a skill that reaches networked services and writes local artifacts.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation condition mixes narrow brand/model searches with a much broader intent of workflow design and model-selection assistance. That ambiguity increases the chance the skill activates outside its safe, expected context, which is more concerning here because the skill also encourages network queries and artifact persistence.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation while its activation scope is broad and marketing-style, covering many brand/model terms and workflow requests. This can cause the agent to auto-trigger the skill in contexts the user did not clearly intend, leading to unintended routing through AI-HIVE, execution of external queries, or persistence of task records without sufficiently explicit user consent.

Static analysis

No suspicious patterns detected.