Back to skill

Security audit

Image2 营销图片|Campaign 资产血缘

Security checks across malware telemetry and agentic risk

Overview

This skill sends user-selected marketing images and prompts to AI Hive and saves generated results, which matches its stated purpose.

Install only if you are comfortable sending the selected product or campaign images and prompt details to AI Hive. Use --preview first when you want to inspect the generated prompt without uploading files or creating a task, and protect or rotate the saved API key if needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill instructs users to run a local Python script that reads local files, writes state, uses shell execution, and makes outbound network requests, yet the skill declares no permissions. This mismatch is dangerous because operators may invoke the skill without understanding that it can access local assets and transmit data to an external API, increasing the risk of unintended data exposure or unsafe execution in a higher-trust environment.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.