Back to skill

Security audit

品牌视觉一致性审核|AI-HIVE

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent and disclosed, but it can upload user-selected media to AI-HIVE and submit potentially paid image or video generation tasks.

Install only if you are comfortable sending selected brand assets, prompts, and reference media to AI-HIVE. Confirm you have rights to all input materials, review price/routing parameters before generation, keep the API key out of logs and repositories, and require explicit approval before any upload or paid task.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill documents code workflows that read environment variables, access local files, invoke shell tools, and communicate over the network, yet it declares no permissions. This creates a transparency and consent gap: a user or host system may invoke a skill expecting passive audit behavior while it can actually perform sensitive operations like using API keys, uploading files, downloading outputs, and modifying media.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
The skill is presented as a brand visual consistency auditor, but the documented behavior expands into generic AI-HIVE chat, model enumeration, uploads/downloads, video editing, blueprint generation, and image/video generation. This mismatch is dangerous because it increases the chance that users, orchestrators, or policy layers grant trust based on the narrower description while the skill can perform materially broader and cost-bearing or data-moving actions.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
A skill framed as an auditing tool also exposes image and video generation workflows, which changes it from passive assessment into active content creation. In context, this can lead to unauthorized brand mimicry, unexpected charges, or users providing sensitive assets under an audit pretext that are then used for generation and external upload.

Description-Behavior Mismatch

Medium
Confidence
84% confidence
Finding
The skill says it audits against user-provided brand standards, but it also invites users to transform a reference case into new 'original' content with scripts, prompts, code, or task lists. That broadens the use case toward derivative-content production, which can be exploited for style imitation or IP-adjacent copying under the guise of brand assistance.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The skill is advertised as a brand visual consistency audit tool, but the exposed interface actually performs image generation and editing through a fixed image model. This capability mismatch is dangerous because users and reviewers may grant the skill access to brand assets under an audit pretext while the code can instead create or modify marketing imagery, enabling unauthorized asset generation or policy bypass.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
An audit-focused skill should primarily inspect and report on user-provided materials, but this code forwards prompts and reference images into an image generation endpoint. That expands the skill from assessment into content creation, which can be abused to generate derivative branded materials or edits inconsistent with the user's expectations and authorization scope.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The file is presented as a brand visual consistency audit skill, but the implementation is a generic AI-Hive generation/uploader CLI with text, image, and video generation features. This mismatch is dangerous because users or downstream policy gates may grant the skill access and trust appropriate for auditing, while the code can instead create and upload arbitrary content outside the declared scope.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The skill-specific configuration and parser branding claim brand visual consistency auditing, but the exposed command is 'generate' and routes to video generation models. This creates deceptive capability packaging, increasing the chance the skill is invoked in sensitive brand-review contexts while actually functioning as a media-generation tool.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
Generic chat capability is unrelated to a narrowly scoped brand visual consistency audit skill and expands the skill beyond least privilege. In context, that broader capability can be abused to process arbitrary prompts or content generation/support tasks that bypass the expected constraints of an audit-only tool.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Image generation is not necessary for a brand audit skill and materially broadens the skill into content creation. Given the skill's stated business use in marketing and advertising, this mismatch can enable unauthorized asset generation under the guise of compliance review.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
Video generation is a high-risk capability that is unjustified for a brand visual consistency audit tool. Because the skill is packaged as an auditing utility, operators may permit it in workflows where a generation-capable tool would not be approved, creating scope-bypass and misuse risk.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The manifest allows implicit invocation without constraining when the skill should activate or when it must not. In a skill that can generate production-ready workflows and runnable AI-HIVE commands, over-broad auto-invocation increases the chance the agent applies the skill in the wrong context, causing unintended API actions, uploads, or brand-audit outputs on unrelated requests.

Static analysis

No suspicious patterns detected.