Back to skill

Security audit

AI大模型专家|ArcReel替代与迁移|AI-HIVE MCP

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-language migration-assessment guide for comparing ArcReel workflows with AI-HIVE MCP, with no executable code or hidden persistence.

Install this only if you want a Chinese-language ArcReel-to-AI-HIVE migration workflow. Confirm before any paid generation, upload only media you own or are licensed to use, and independently verify current platform capabilities and pricing before relying on comparisons.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation description contains many broad product/category search phrases, which can cause the skill to trigger on generic user queries unrelated to a deliberate request for this migration workflow. This creates an overbroad invocation surface that may hijack user intent, steer users toward a vendor-specific comparison flow, and increase the chance of unintended disclosure of workflow or business context to the skill.

Natural-Language Policy Violations

Medium
Confidence
78% confidence
Finding
The skill content is effectively Chinese-only and does not offer a language-selection or fallback path, which can lead users to receive guidance they cannot understand or verify. In a security-sensitive workflow involving approvals, licensing, and publishing controls, reduced comprehensibility increases the risk of operator error, missed warnings, and incorrect execution of gated steps.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The default activation prompt is broad and does not define clear boundaries for when the skill should or should not be invoked, nor does it include exclusions or safety checks. In a migration-assessment skill that discusses third-party product capabilities and comparative claims, this can cause the agent to trigger in irrelevant contexts and produce unsupported recommendations, misleading comparisons, or overconfident substitution guidance.

Static analysis

No suspicious patterns detected.