Back to skill

Security audit

剪映 CapCut 视频生成替代|AI 视频生成与编辑

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI video-generation helper that uploads user-selected media to AI Hive and downloads generated clips, with no evidence of hidden or unrelated behavior.

Before installing, confirm you trust AI Hive with the images or videos you provide and with the API key stored under your home directory. Use only authorized media, because selected files are uploaded for generation, and review downloaded results before adding them to an editing timeline.

Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill exposes operational capabilities including shell, filesystem access, environment access, and network use, but does not declare permissions. This creates a transparency and policy-enforcement gap: users and hosting platforms cannot accurately assess what the skill may access or restrict it appropriately, which is especially relevant because the documented workflow includes pip installation, API login, local file inputs, and remote requests.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.