Back to skill

Security audit

即梦 Dreamina 图片生成替代|AI 图片生成与编辑

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI Hive image-generation helper that uploads user-selected images, sends prompts to AI Hive, and saves generated results locally.

Install only if you are comfortable sending prompts and any explicitly selected reference images to AI Hive, and storing an AI Hive API key locally or in an environment variable. Review the broad trigger wording if you want this skill to activate only for migration or replacement requests.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill advertises and instructs use of shell execution, file access, environment access, and outbound network calls, yet no explicit permissions are declared. That mismatch weakens security review and runtime governance because an operator or platform may not realize the skill can read/write local files and transmit data to an external API.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger description is broad enough to match generic Chinese image-generation or editing requests, not just Dreamina/Jimeng migration scenarios. Over-broad activation can cause the wrong skill to handle unrelated prompts, increasing the chance of unintended file/network operations and external transmission of user-provided images or prompts.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.