Back to skill

Security audit

AI服装换模特效果图|AI-HIVE

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed AI-HIVE apparel image workflow that uses an API key and user-selected media, with no hidden execution, destructive behavior, or credential exfiltration found.

Install only if you are comfortable sending selected reference media and prompts to AI-HIVE and potentially incurring API charges after confirmation. Use authorized images, keep the API key out of logs and repositories, and review parameters before running generation commands.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill advertises executable workflows and code examples that use environment variables, local file access, network calls, and shell commands, yet no permissions are declared. That creates an auditability and least-privilege problem: operators and users cannot reliably understand what the skill can access before use, increasing the risk of unintended data exposure or execution in a broader-trust environment.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The documented behavior extends well beyond apparel model swapping into generic chat, video generation, account/balance retrieval, model enumeration, and unrestricted media upload. This scope mismatch is dangerous because reviewers and users may trust the skill for a narrow image-editing purpose while it actually exposes broader capabilities that can access account metadata, incur charges, or process unrelated content.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill enables implicit invocation without any trigger constraints, so the platform may auto-select it for loosely related requests. Because this skill can generate runnable AI-HIVE commands and production workflows for image generation, accidental invocation could cause unintended external API use, cost incurrence, or content-generation actions outside clear user intent.

Static analysis

No suspicious patterns detected.