Back to skill

Security audit

HappyHorse 视频生成与编辑

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a real AI Hive video-generation helper, but it should be reviewed because it uses very broad invocation keywords while uploading user media and using a stored API key for billable remote jobs.

Install only if you intend to use AI Hive/HappyHorse for video generation and are comfortable uploading the media paths you provide to that service. Review the API-key storage at ~/.ai-hive/config.json, expected costs before submitting jobs, and avoid using confidential unreleased customer or product assets unless AI Hive's terms and retention practices are acceptable.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill advertises substantial capabilities—environment access, file read/write, network, and shell-driven workflows—without declaring permissions or clearly constraining what data and actions those capabilities may touch. This creates a trust and review gap: users and orchestrators may invoke a skill that can access local files, send data externally, and modify local state without explicit disclosure.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding
The documented purpose is narrowly framed as HappyHorse video generation/editing, but the skill reportedly also exposes broader AI Hive client functionality such as generic chat/image generation, account and wallet retrieval, model enumeration, and interactive API-key setup. This mismatch can mislead users and policy systems about the actual attack surface, enabling unexpected access to sensitive account metadata or broader remote actions than the user intended.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill uses extremely broad trigger keywords across generic video, AIGC, and e-commerce domains, which can cause over-invocation for loosely related user queries. Overly broad routing is dangerous because it may cause unsolicited external uploads, API calls, task submissions, or model discovery in contexts where the user did not intend to use this specific third-party workflow.

Vague Triggers

Medium
Confidence
82% confidence
Finding
Claiming applicability to broad Chinese and English search behavior without clear limits increases the chance that the skill is selected for unrelated requests. In this skill's context, mistaken invocation is more dangerous because the workflow includes credential handling, media upload, remote job submission, and local file writes/downloads.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The competitor/migration section broadens the match surface to a large ecosystem of unrelated tools and comparison queries, making accidental invocation much more likely. Because the skill can interact with external services and potentially sensitive user assets, broad competitive keyword capture increases privacy, billing, and unintended-action risk.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill states that source media will be automatically uploaded before generation, but it does not prominently warn that user files are transmitted to an external service. This is a meaningful privacy and confidentiality issue, especially for commercial video assets, unreleased ads, customer media, or other sensitive content that users may not expect to leave the local environment automatically.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.