Back to skill

Security audit

AI大模型专家|Minimax H3 视频生成与编辑

Security checks across malware telemetry and agentic risk

Overview

The skill mostly matches its video-generation purpose, but it can be invoked implicitly to upload media and submit AI-HIVE jobs without strong activation guardrails.

Install only if you are comfortable giving this skill an AI-HIVE API key and letting it upload selected media to AI-HIVE for video generation. Prefer invoking it explicitly, confirm the exact files and prompt before submitting a generation job, and monitor account costs or quotas.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding
The documented skill presents itself as a narrowly scoped Minimax H3 video generation/editing workflow, but the static finding indicates the underlying implementation may also support broader AI-HIVE operations such as generic chat, image generation, model enumeration, account/balance retrieval, and browser-based credential initialization. That scope expansion matters because users may grant trust, credentials, and local execution based on a much narrower description, creating a confused-deputy risk and increasing the chance of unnecessary data exposure or unintended account actions.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables allow_implicit_invocation without any visible activation constraints, exclusions, or user-confirmation guardrails. Because this skill can trigger real AI-HIVE actions such as uploading media, submitting generation jobs, polling status, and downloading results, implicit activation could cause unintended external operations, data transfer, or cost-incurring requests from loosely related user prompts.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.