Back to skill

Security audit

AI大模型专家|Seedream 5.0 Lite 图片生成与编辑

Security checks across malware telemetry and agentic risk

Overview

The skill mostly matches an AI-HIVE image-generation workflow, but its broad implicit activation could send unrelated prompts or files to a third-party, potentially billable service.

Install only if you want this skill to use your AI-HIVE account for Seedream image generation. Avoid enabling it for broad automatic routing, confirm before uploading reference files or starting batches, and review the stored API key location.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Lp3

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding
The skill documentation describes capabilities that require environment access, filesystem reads/writes, network access, and shell execution, but it declares no permissions. This creates a transparency and consent gap: a host or user may invoke the skill assuming limited scope while it can access local files, store secrets, and make outbound requests, increasing the risk of covert data access or unsafe execution pathways.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The skill is presented as a narrowly scoped Seedream 5.0 Lite image-generation tool, but the analysis indicates broader functionality including generic chat, video generation, account/balance retrieval, model enumeration, and generic media upload. This mismatch is dangerous because it can bypass user expectations and approval boundaries, enabling data exposure, unintended billing actions, or interaction with APIs beyond the stated purpose.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation description is excessively broad and packed with generic terms across AI, ecommerce, advertising, image, and video workflows. Overbroad triggers increase the chance the skill is auto-selected in unrelated contexts, causing unintended execution of networked actions, uploads, or task submissions without a clear user request for this specific skill.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The search coverage section enumerates a very large set of unrelated platforms, tools, model names, and content tasks, far beyond the stated function of this skill. In a routing or auto-invocation environment, this can hijack traffic intended for other tools and expose user data or trigger external API usage under false relevance.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The original search-intent section defines activation in expansive, open-ended language covering many adjacent product and marketing scenarios rather than a constrained operational boundary. This increases the risk of unintended invocation and makes it easier for the skill to act on ambiguous requests involving uploads, generation jobs, and potentially billable API actions.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation without any trigger constraints, so the agent may auto-select this skill in contexts the user did not clearly intend. Because this skill can submit jobs to an external AI-HIVE service, upload reference material, poll task status, and download outputs, unintended invocation can cause unauthorized outbound data transfer, unexpected third-party processing, and unintended costs.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.