Back to skill

Security audit

Happy Horse 视频生成

Security checks across malware telemetry and agentic risk

Overview

This appears to be a real AI Hive Happy Horse video generator, but its broad activation language plus credentialed media upload and paid generation workflow need Review before installation.

Install only if you intend to use AI Hive/Happy Horse for video generation. Expect to provide an AI Hive API key, upload any referenced local media to the remote service, possibly incur generation costs, and receive outputs under ~/Downloads/AiHive by default; avoid relying on the broad competitor or ecommerce search wording as consent to run generation.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Lp3

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding
The skill advertises executable behaviors including environment access, file read/write, network calls, and shell usage, but does not declare permissions or clearly bound those capabilities. In a skill that uploads local media, stores API keys, opens browser flows, and downloads outputs, hidden or undeclared capabilities weaken user consent and make abuse or overreach harder to detect.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
The documented behavior exceeds the stated purpose of a narrow Happy Horse video-generation skill by also covering account queries, broad model enumeration, generic chat, image generation, browser-based setup, and local config management. This creates a trust boundary problem: users may invoke a specialized media tool while actually granting a much broader AI Hive client with access to account data, credentials, and unrelated generation capabilities.

Description-Behavior Mismatch

Medium
Confidence
82% confidence
Finding
The file presents itself as a Happy Horse video skill, but embeds a broader generic AI Hive client supporting chat, image generation, model enumeration, uploads, and account operations. This expands the attack surface and grants capabilities beyond the stated purpose, which can enable misuse or unexpected data access when a caller trusts the skill to be narrowly scoped.

Context-Inappropriate Capability

Medium
Confidence
85% confidence
Finding
The client exposes user-info and model inventory endpoints that are not required for a dedicated Happy Horse video generator. In a skill environment, these extra endpoints can disclose account metadata, balances, and available models, aiding reconnaissance and unauthorized use beyond user expectations.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The trigger description is intentionally broad, matching many competitor names, generic search terms, and loosely related e-commerce and marketing intents. Overbroad invocation increases the chance the skill runs in contexts where users did not intend media upload, paid API use, or local file effects, leading to confused-deputy behavior and accidental data disclosure.

Vague Triggers

Medium
Confidence
79% confidence
Finding
The markdown repeatedly encourages matching broad search, migration, competitor, and channel/platform scenarios without clear limits. In context, this is risky because the skill can upload user-provided files, use API credentials, and trigger billable remote operations, so ambiguous activation can have privacy and cost consequences.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill states that it will automatically upload user media and automatically download/store generated videos, but it does not prominently disclose privacy implications, storage locations, retention expectations, or external recipients. For a media-generation workflow handling local images, videos, audio, and API-backed cloud processing, missing disclosure can lead to unintended sharing of sensitive files and silent local persistence.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.