Back to skill

Security audit

GPT Image 2 电商主图

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI Hive image-generation helper that uses an API key, uploads user-selected reference images, and saves generated outputs, with no evidence of hidden persistence, destructive behavior, or automatic data collection.

Install only if you are comfortable sending selected product/reference images and prompts to AI Hive and storing an AI Hive API key locally. Use the documented generate command for image work, keep the config file private, and avoid uploading files that contain sensitive or unrelated personal data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill advertises executable commands that install dependencies, read environment variables via the runtime, access local files, write outputs, invoke shell commands, and make network requests, yet no permissions are declared. This creates a trust and containment gap: a user or platform may assume a low-risk documentation skill, while the referenced script can perform broader actions that could access sensitive data or exfiltrate content if misused or modified.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
The declared purpose is narrowly scoped to ecommerce image generation, but the underlying behavior reportedly includes generic AI API calls, model enumeration, user/wallet queries, browser-based API-key setup, and broader media upload and generation workflows. That mismatch is dangerous because it can mislead users and reviewers about the true attack surface, enabling unexpected handling of credentials, account data, or unrelated media operations beyond the promised image-editing use case.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The file presents itself as a narrowly scoped ecommerce main-image skill, but actually ships a broad, reusable API client with chat, video, model discovery, account inspection, upload, and task management capabilities. This violates least-privilege and scope expectations: a caller selecting a seemingly limited image skill could unintentionally grant access to much broader remote operations than the metadata suggests.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
Including text-chat capability in an ecommerce main-image skill expands the attack surface beyond the advertised purpose and enables arbitrary prompt submission to a text model using the user's API key. In a skill ecosystem, hidden extra capabilities are risky because orchestration layers or users may trust the skill with permissions and inputs appropriate only for image generation.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Video-generation support is materially outside the declared main-image use case and permits additional media uploads plus long-running remote generation jobs. That broader capability can increase cost exposure, data exposure from uploaded media, and misuse potential if the skill is invoked under the assumption it only creates product images.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
User-info querying exposes account metadata and potentially balance information that is unrelated to generating ecommerce images. Even if not highly sensitive on its own, this is unnecessary account reconnaissance capability embedded in a narrowly branded skill and can aid profiling or abuse of the user's API account.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.