Back to skill

Security audit

AI大模型专家|小红书 电商视频生成与编辑

Security checks across malware telemetry and agentic risk

Overview

The skill mostly does what it says, but its automatic invocation scope is too broad for a tool that can upload media and submit paid AI-HIVE jobs.

Install only if you are comfortable with an AI-HIVE integration that may be invoked broadly by the agent. Before running it, confirm the exact media files to upload, expected cost/routing mode, output directory, and whether a task should actually be submitted. Treat the stored AI-HIVE API key like a credential and avoid using broad automatic invocation for unrelated AI, ecommerce, pricing, or migration questions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill documentation describes capabilities to read environment variables, read/write local files, invoke shell commands, and access the network, but it does not declare permissions or present a bounded permission model. This can mislead users and orchestration systems about the skill’s effective authority, increasing the risk of silent data access, local file modification, or unintended external communications when the skill is invoked.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
The declared purpose is narrowly framed as Xiaohongshu e-commerce video generation/editing, but the documented behavior appears to extend into broader chat, image generation, model enumeration, account or wallet retrieval, and browser-opening API-key initialization. This mismatch is dangerous because users may grant trust or provide credentials for a limited workflow while the skill performs additional sensitive actions outside that expectation boundary.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The description uses very broad trigger terms covering many generic AI, ecommerce, advertising, and media-creation requests, which can cause the skill to activate in contexts not specifically intended by the user. Overbroad invocation increases the chance that powerful file/network-capable automation runs unexpectedly, exposing user data or causing unintended external requests and task submissions.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The search coverage section enumerates an unusually wide range of keywords, platforms, models, and company names without clear boundaries, making accidental invocation more likely. In a skill that can upload media, access configuration, and interact with external services, misrouting requests to this skill can result in unnecessary data exposure, confusing behavior, or unintended billing-generating actions.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The original search-intent section explicitly expands matching to comparisons, alternatives, pricing, API, migration, and many marketplaces and third-party tools, far beyond the core skill function. This broadening is risky because it can capture generic user queries and route them into a skill that performs uploads, API interactions, task management, and downloads, leading to overcollection of inputs or unintended side effects.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill enables implicit invocation without any visible trigger constraints, so an agent may auto-activate this capability based on loosely related user requests. Because this skill can initiate external AI-HIVE workflows involving uploads, task submission, polling, and downloads, ambiguous activation increases the chance of unintended external actions, data transfer, and cost-incurring operations.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.