Back to skill

Security audit

GPT Image 2 直播带货图片

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI Hive image-generation wrapper for livestream commerce assets; it stores an API key and uploads user-selected media, but I found no hidden destructive or exfiltration behavior.

Install only if you are comfortable using AI Hive for generation, uploading the reference images you choose, and storing an API key locally. Avoid passing private files as references or uploads, and review generated commerce materials against current platform advertising rules before publishing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill advertises shell, network, environment, and file read/write capable workflows but does not declare corresponding permissions. This creates a transparency and containment problem: operators and users cannot accurately assess what the skill can access, and an agent runtime may execute broader-capability actions than expected.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
The declared purpose is narrowly scoped to generating livestream commerce images, but the underlying behavior reportedly includes credential initialization, browser-based auth, local credential storage, media upload/download, task polling, model listing, user-info retrieval, and even general-purpose text/video features. This mismatch is dangerous because it expands the attack surface beyond user expectations and can enable credential handling, data exfiltration, or unintended API operations under the guise of a simple image skill.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.