Back to skill

Security audit

抖音爆款短视频生成与编辑

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI Hive video-generation helper with expected network, media upload, API-key setup, and output download behavior.

Install only if you are comfortable giving the skill an AI Hive API key, uploading the media files you choose to AI Hive, and downloading generated results to your machine. Review provider pricing and platform advertising rules before using generated material commercially.

Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill invokes a Python script with capabilities that imply environment access, file I/O, shell execution, and network communication, but it declares no permissions. This creates a transparency and containment problem: a host or reviewer cannot accurately assess or restrict what the skill may do, increasing the chance of unintended data access, command execution, or outbound requests during use.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The documented purpose is narrowly framed as Douyin video generation/editing, but the underlying behavior reportedly includes broader AI Hive OpenAPI access, model enumeration, user info/wallet queries, and unrelated chat/image capabilities. This mismatch is dangerous because it expands the effective attack surface beyond user expectations, enabling data access or API actions that are not necessary for the stated task and may be abused or triggered unintentionally.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.