Back to skill

Security audit

AI大模型专家|Blooper替代与迁移|AI-HIVE MCP

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese-language migration-planning skill for AI video workflows, with no hidden executable behavior found.

Before installing, be aware that the skill is primarily Chinese-language and is designed to guide paid or external AI-HIVE media tasks. Use it only with assets you own or are licensed to use, confirm current platform capabilities and pricing before running tasks, and keep the manual approval and rollback steps enabled.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The manifest description and the markdown content are entirely in Chinese, including the invocation guidance and operating instructions, with no indication that users may choose another language. This can violate language/locale policy because it imposes a specific language without opt-in or a clearly stated region-specific limitation.

Static analysis

No suspicious patterns detected.