Back to skill

Security audit

App界面演示广告|AI-HIVE

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed AI-HIVE video-ad workflow that uses user-directed local files, API calls, and media tools without evidence of hidden or destructive behavior.

Install only if you intend to use AI-HIVE for app UI demo ad production. Do not paste or store an API key unless you trust the AI-HIVE account flow, review parameters before billable generation, and only upload screenshots, recordings, audio, or videos you have rights to use.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill embeds executable workflows that use environment variables, local file read/write, shell commands, and outbound network access, but it declares no permissions or capability boundaries. This creates a transparency and containment problem: a caller may invoke a seemingly simple ad-production skill without understanding it can access local assets, contact external services, and run local tooling such as ffmpeg.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The documented purpose is a narrow App/UI demo ad workflow, but the detected behaviors are substantially broader, including generic model access, uploads, wallet/balance queries, task polling, and standalone media processing. That mismatch weakens user consent and policy controls because a skill invoked for a specific creative task may be used as a general-purpose gateway to external APIs, account metadata, and arbitrary media handling beyond the stated scope.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill enables implicit invocation with no bounded trigger conditions or exclusions, which increases the chance the agent will activate this capability in contexts the user did not clearly request. In this skill, that is more dangerous because it can steer conversations into producing runnable AI-HIVE commands and ad-production workflows, creating unintended external actions, cost exposure, or policy-bypassing marketing assistance.

Natural-Language Policy Violations

Medium
Confidence
85% confidence
Finding
The default prompt hard-codes Chinese output and does not preserve user language preference or require opt-in. While this is not a direct code-execution issue, it can mislead users, reduce transparency, and increase the likelihood of misunderstood instructions or overlooked risky steps in a workflow that generates executable commands and production deliverables.

Static analysis

No suspicious patterns detected.