Back to skill

Security audit

Amazon Listing 图片工作室|AI-HIVE

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI-HIVE workflow for Amazon listing image production, with user-directed uploads and paid generation steps that are mostly proportionate to its purpose.

Install only if you intend to use AI-HIVE for Amazon/ecommerce image workflows. Review commands before running them, do not provide unlicensed product or brand assets, and confirm model, route, upload files, and cost before any generation task. Be aware that API-key initialization stores a local key file under ~/.ai-hive/config.json.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill advertises executable workflows that use environment variables, shell commands, filesystem access, and network calls, but it does not declare permissions. This creates a transparency and containment problem: a host may invoke the skill without understanding its true capability surface, increasing the chance of over-privileged execution or unsafe operator trust.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The documented purpose is narrowly framed as an Amazon listing image workflow, but the referenced behaviors include general chat, video generation, account/wallet access, broad model enumeration, and generic uploads. This mismatch is dangerous because users or orchestration systems may grant trust and invoke the skill under a narrow business assumption while it can reach materially broader and more sensitive functions.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The file is implemented as a generic AI OpenAPI client supporting chat, image, video, upload, and polling, while the skill metadata describes a narrowly scoped Amazon Listing image studio. This scope mismatch increases attack surface and enables users or downstream agents to invoke capabilities outside the declared purpose, undermining policy controls and trust assumptions tied to the skill manifest.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The standalone chat command exposes a broad text/multimodal model interface that is unrelated to generating Amazon Listing images. In a skill ecosystem that relies on metadata scoping, this becomes a confused-deputy issue: the skill can be used as a generic model access path rather than the constrained commerce-image tool it claims to be.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The video-generation path materially exceeds the declared purpose of an Amazon Listing image studio and introduces a larger, unjustified capability set, including image/video/audio uploads and frame controls. This broadens abuse potential, increases cost and data-handling risk, and weakens any platform policy that depends on the skill being limited to listing-image production.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The module and CLI self-describe as a general-purpose AI capability caller, which conflicts with the specialized identity presented in the skill manifest. Mislabeling capabilities is dangerous because operators and automated governance may approve or route the skill under narrower assumptions than what the code actually enables.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger terms are broad ecommerce and marketing phrases, which can cause the skill to activate in contexts beyond its intended narrow use. Over-broad invocation increases the likelihood of accidental data sharing, inappropriate tool selection, or use of paid/generative operations for tasks the user did not actually request.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The usage section allows activation for broad scenario-based requests such as advertising, social media, and stable content delivery, without strong constraints tying the request to Amazon listing image work. In practice, this can route unrelated tasks into a skill that has networked and potentially billable generation capabilities, raising operational and privacy risk.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill is configured for implicit invocation and its description/default prompt cover a very broad set of e-commerce and marketing tasks without tight trigger boundaries. This can cause the agent to activate in contexts the user did not clearly intend, leading to unexpected workflow generation, external API usage guidance, or handling of sensitive commercial content under the wrong skill.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The default prompt hard-codes Chinese output regardless of the user's language preference. While not directly a code-execution issue, it can cause user misunderstanding of generated instructions, checklists, or AI-HIVE commands, increasing the chance of operator error in a workflow that may involve external content generation and commercial assets.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.