Back to skill

Security audit

AI大模型专家|淘宝 电商视频生成与编辑

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI-HIVE video generation helper that uploads chosen media, submits video jobs, polls results, and downloads outputs, with some install-time and usage cautions.

Install this only if you are comfortable sending prompts and selected media files to AI-HIVE and using an API key that may incur charges. Keep the API key private, review pricing before batch or expensive runs, and avoid uploading private or third-party media unless you have rights to use it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill documents capabilities that read environment variables, read/write local files, invoke shell commands, and make network requests, yet it declares no permissions boundary. This creates an ambient-authority problem: users and calling platforms are not clearly informed what the skill can access, making it easier to over-trust a skill that can handle API keys, local media, and downloaded outputs.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
The skill is presented as a narrowly scoped Taobao e-commerce video generation/editing tool, but the analysis indicates it also exposes broader AI-HIVE functionality including generic chat, image generation, account info retrieval, wallet balance access, and cross-model catalog operations. That mismatch is dangerous because users may invoke or authorize the skill expecting limited video-processing behavior while it can access unrelated endpoints and potentially disclose account metadata or incur unexpected charges.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill enables implicit invocation while exposing a broad, natural-language description that covers many video-generation and editing workflows. This increases the chance the agent will auto-select and execute the skill in situations the user did not explicitly intend, potentially causing unintended uploads of user media, external API calls, task creation, polling, and result downloads to a third-party service.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.