Back to skill

Security audit

AI大模型专家|CoAnimator替代与迁移|AI-HIVE MCP

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrowly documented migration-assessment guide that discloses its external AI-HIVE workflow and includes approval, authorization, and rollback controls.

Before installing, note that the skill is designed for a specific CoAnimator-to-AI-HIVE migration evaluation. It may invoke external AI-HIVE-style workflows, so only provide assets you own or are authorized to use, verify current pricing and tool schemas, and keep the required human approval before paid generation, uploads, publishing, or bulk actions.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
L03 将触发条件描述为“当用户搜索 CoAnimator替代、Agent动画、Codex动画、Claude Code动画、动画视频工作流、OiiOii同类平台、AI视频Agent、创意Agent平台、AI-HIVE MCP 时使用”。其中多项短语如“Agent动画”“AI视频Agent”“创意Agent平台”“动画视频工作流”范围较宽,且未给出排除条件或负例,难以判断何时应激活本技能、何时不应激活。

Static analysis

No suspicious patterns detected.