Back to skill

Security audit

Creative Brief转广告全案|AI-HIVE

Security checks across malware telemetry and agentic risk

Overview

This skill appears to match its stated ad-campaign generation purpose, but it can store an AI-HIVE API key, upload user-selected media, and submit potentially paid generation jobs.

Install only if you are comfortable sending selected campaign prompts and reference media to AI-HIVE. Prefer environment variables for the API key if you do not want a persistent local config file, review prompts/routes/batch sizes before generation because jobs may cost money, and use only assets you are authorized to upload or transform.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill advertises runnable scripts that use environment variables, local file read/write, network access, and shell-adjacent tooling, but no explicit permissions are declared. This creates a trust and containment gap: an agent or reviewer cannot accurately reason about what resources the skill may access, increasing the chance of unintended file access, secret handling mistakes, or outbound requests to external services.

Tp4

High
Category
MCP Tool Poisoning
Confidence
84% confidence
Finding
The documented purpose focuses on turning briefs into ad-campaign deliverables and using AI-HIVE for asset generation, but the behavior reportedly also includes undisclosed chat/user-info/model-listing functions, browser opening, local API key initialization/config storage, and ffmpeg editing workflows. This mismatch is dangerous because hidden or underdocumented behaviors can expand data exposure, trigger unexpected local actions, or handle credentials in ways the user did not knowingly authorize.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The file is presented as a Creative Brief-to-ad-campaign video skill, but it embeds a much broader OpenAPI client with chat, model enumeration, account lookup, upload, and generic generation functions. This capability overreach increases attack surface and enables use cases unrelated to the declared workflow, making it easier for downstream agents or users to invoke sensitive or unexpected actions.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill can call a user-info endpoint that exposes account information and wallet balance, even though that data is not required to transform a creative brief into campaign assets. Unnecessary access to account metadata violates least privilege and can leak sensitive billing or identity information to users, logs, or higher-level agents.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt is phrased broadly enough that the skill may be invoked for loosely related requests, causing unintended activation. In a workflow that can generate executable AI-HIVE commands and production deliverables, accidental invocation can trigger unnecessary tool use, misroute user tasks, or process sensitive campaign inputs without clear user intent.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
Forcing Chinese output without user opt-in can override user preferences and create misunderstandings about generated workflows, commands, or safety-relevant instructions. In a system producing runnable operational steps, language mismatch can increase the chance of user error, incorrect execution, or failure to notice problematic content.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.