Back to skill

Security audit

电商广告创意工作室|AI-HIVE

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI-HIVE ecommerce ad creative workflow that uses local helper scripts, an API key, uploads, and possible paid generation in ways that fit its stated purpose.

Install only if you intend to use AI-HIVE for ecommerce ad creative work. Use a dedicated API key, keep it out of logs and repos, confirm final prompts/routing before generation because calls may cost money, and upload only assets you are authorized to send to an external service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill exposes operational capabilities including environment access, file read/write, network access, and shell execution without declaring permissions. Even though the markdown presents these as example scripts, the effective capability surface is broader than what a user or reviewer can infer from the manifest, which weakens least-privilege controls and can enable unsafe key handling, local file access, or arbitrary command execution paths.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The documented purpose is narrowly framed as an ecommerce ad creative workflow, but the referenced behavior expands into generic model listing, text chat, user account and wallet queries, and browser-based API-key initialization/storage. This mismatch is dangerous because it creates hidden functionality outside expected user intent, increasing the risk of unauthorized data access, accidental spending, credential exposure, and misuse of the skill as a general-purpose gateway.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The file is presented as a specific ecommerce ad-creative image skill, but the implementation and top-level tool framing expose a broader generic AI utility surface. Scope mismatch is dangerous because platform policy, user trust, and downstream authorization may assume tighter restrictions than the code actually enforces, enabling use outside the declared skill purpose.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The code includes unrestricted text-chat functionality even though this skill is described as an ecommerce ad-creative image tool. That expands capability beyond expected scope and can be abused to perform unrelated prompting or policy-bypassing tasks under the cover of a narrower, seemingly safer skill.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The implementation exposes generic video-generation APIs despite this wrapper being positioned as an image-oriented ad-creative skill. Hidden or unused broader media-generation paths increase the attack surface and allow users or orchestrators to invoke capabilities that have not been disclosed, constrained, or reviewed for this skill context.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The file is packaged as a narrowly scoped ecommerce ad-creative skill, but the implementation is a general-purpose AI Hive client with broader capabilities including chat, model enumeration, uploads, and task handling. This scope mismatch increases the attack surface and enables use cases beyond the user's expected authorization boundary, undermining least privilege and skill transparency.

Context-Inappropriate Capability

Medium
Confidence
86% confidence
Finding
Exposing user-info and wallet/balance retrieval is unnecessary for a skill whose stated purpose is creative generation. Even if not directly dangerous, it grants access to account metadata outside the advertised function and may leak sensitive billing information to users or calling workflows that did not need it.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The generic text chat endpoint allows arbitrary model interaction unrelated to ecommerce ad creative generation. In the context of a specialized skill, this bypasses intended functional constraints and can be abused as a broader AI proxy using the skill's configured credentials.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The module self-describes as a general-purpose AI capability tool while the skill metadata presents a specialized ecommerce ad studio. This contradiction is a security-relevant trust boundary issue because operators may grant the skill broader access than intended without realizing the implementation is more capable than advertised.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The activation conditions include broad business-content requests such as ad creativity, marketing, and converting reference cases into original content, which can cause the skill to trigger in situations not clearly requiring API-backed generation or sensitive local tooling. Over-broad activation increases the chance that users are routed into workflows involving uploads, network actions, or potentially billable generation without a sufficiently specific match to the intended task.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill enables implicit invocation without any visible trigger constraints, so the agent may activate it for loosely related requests and begin producing workflow/code outputs the user did not explicitly ask for. In a marketing/ads context, this broad activation surface increases the chance of unintended use for sensitive ad-generation tasks, platform-specific automation, or compliance-adjacent content without clear user confirmation.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.