Back to skill

Security audit

GEO 多平台内容生成器|AI-HIVE

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI-HIVE content-generation helper with some activation and API-key storage cautions, but no hidden or destructive behavior was found.

Install only if you intend to use AI-HIVE for content and image-generation workflows. Review parameters before running commands, avoid uploading unlicensed or sensitive media, and remember that init stores an API key locally in a plaintext config file protected by file permissions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill exposes effective capabilities for environment access, filesystem I/O, shell execution, and network calls without declaring permissions or clearly constraining their use. This is dangerous because users and reviewers cannot accurately assess what the skill may access or execute, increasing the risk of secret exposure, unintended file modification, or arbitrary external requests if supporting scripts are invoked.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The documented purpose is a GEO content-writing workflow, but the underlying behavior reportedly includes account inspection, model enumeration, generic chat, video generation, media upload, and browser-based API-key setup. That mismatch is dangerous because it obscures the real attack surface: a user invoking a content-writing skill may unknowingly trigger broader privileged operations, including credential handling and unrelated remote actions.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The trigger phrases include very broad terms such as FAQ, brand content, and Zhihu answers, which can cause the skill to activate in ordinary conversations not specifically requesting this tool. Overbroad auto-selection is risky because it may route benign user requests into a skill with networked generation and file-handling behavior, increasing the chance of unnecessary data exposure or unintended external actions.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The manifest enables implicit invocation for a skill that can generate production-ready workflows and runnable AI-HIVE commands, but it does not define narrow activation boundaries or exclusions. This increases the chance the agent will invoke the skill in contexts the user did not clearly intend, which can lead to unintended content generation, external API usage, or actions being framed as approved by the user.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The default prompt hard-codes Chinese output and a specific production-oriented behavior without indicating user choice or opt-in. While this is not a direct code-execution issue, it can override user expectations, reduce transparency, and cause the agent to steer requests into a predefined workflow that may not match the user’s language or consent preferences.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.