Back to skill

Security audit

GPT Image 2 图片换背景

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent AI Hive image background replacement helper with disclosed API/network use and no evidence of hidden destructive or exfiltrating behavior.

Install only if you are comfortable sending selected reference images and prompts to AI Hive and storing an AI Hive API key locally. Use --image/--file only with media you intend to upload, and avoid custom --base-url or --param values unless you understand their effect.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill advertises executable capabilities including environment access, file read/write, network, and shell, yet declares no permissions. This reduces transparency and prevents users or a runtime policy layer from understanding or constraining what the skill can do, which is risky because the referenced scripts can install packages, access files, and make outbound requests.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
The documented purpose is narrowly scoped to GPT Image 2 background replacement, but the skill reportedly also supports unrelated capabilities such as generic chat, video generation, model enumeration, account/balance queries, media upload, and browser/API-key initialization. This mismatch is dangerous because it hides materially broader behavior than users would expect, increasing the chance of unauthorized data access, credential handling, or unintended external actions.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill is presented as a narrowly scoped GPT Image 2 background-replacement tool, but the exposed CLI also allows task querying, raw media upload, API-key initialization, and caller-controlled routing. This expands the effective capability surface beyond the declared purpose, which can bypass policy, review, or user expectations about what the skill is allowed to do.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill forwards arbitrary --param key=value pairs directly to the backend model call, allowing users to influence backend behavior outside the declared 'background replacement' scope. In practice this can unlock undocumented generation/editing modes or weaken guardrails enforced by the skill layer, making the skill more general-purpose than advertised.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.