Back to skill

Security audit

AI大模型专家|小红书 电商图片生成与编辑

Security checks across malware telemetry and agentic risk

Overview

The skill mostly matches AI-HIVE image generation, but its broad implicit activation could unintentionally send prompts or files to a paid external service.

Install only if you are comfortable with the agent using AI-HIVE automatically for broadly matched ecommerce or AI image requests. Before running it, confirm the exact prompt, files to upload, batch size, route, and likely cost, and keep the stored API key private.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill documents capabilities that access environment variables, local files, shell commands, and network services, but it does not declare permissions or clearly bound those capabilities. This weakens user and platform visibility into what the skill can do and increases the chance of over-privileged execution, credential exposure, or unintended local file modification during setup and task handling.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The documented purpose presents a narrow image-generation skill, but the behavior reportedly includes broader functions such as chat, video generation, account and wallet retrieval, model catalog enumeration, generic uploads, and local credential management. This mismatch undermines informed consent and can lead users or orchestrators to invoke a skill with far more access and data handling than expected.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill description is so broad that it can match many unrelated AI, ecommerce, advertising, and media-generation requests. Over-broad activation boundaries increase the risk of unintended invocation, causing user data or prompts to be routed to an external platform and triggering networked actions, uploads, or billing when the user did not intend to use this specific skill.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The search coverage enumerates a very large set of keywords, brands, tools, and platforms, which can cause the skill to activate for loosely related requests. In the context of a skill that uploads media, manages tasks, and uses an API key, accidental activation increases privacy, billing, and data-routing risk.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The original search-intent section explicitly targets broad comparison, pricing, API, and migration queries across many third-party tools and platforms. That makes the skill more likely to intercept exploratory or informational requests and steer them into a network-enabled workflow with uploads, task creation, and possible charges beyond the user’s expectation.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation with no documented trigger constraints, exclusions, or scope limits. In a skill that can submit external AI-HIVE jobs, upload reference images, poll task status, and download results, this increases the chance the agent will invoke the skill automatically in contexts the user did not explicitly intend, potentially causing unintended data transfer, external actions, or charges.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.