Back to skill

Security audit

AI大模型专家|会计事务所AI图片视频营销

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI-HIVE marketing workflow that uses user-provided API credentials and media files to create accounting-firm image and video assets.

Install only if you intend to use AI-HIVE for accounting-firm marketing assets. Treat prompts and uploaded reference files as data sent to AI-HIVE, use only authorized media, confirm budget/routing before generation, and keep the API key out of project files and logs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill embeds executable shell commands and implies access to environment variables, local files, networking, and filesystem writes, but does not declare any permissions or capability boundaries. This creates an authorization transparency gap: a caller may invoke the skill expecting content-planning behavior while the implementation can access sensitive local resources and external services.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The described purpose is marketing-content generation for accounting firms, but the detected behavior includes broader local video processing, chat/multimodal API use, user-info or wallet queries, and interactive browser/API-key setup. This mismatch is dangerous because users and reviewers cannot accurately assess the operational surface area, increasing the chance of unintended data access, credential exposure, billing actions, or execution of higher-risk local tooling.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill is presented as a specialized image-marketing tool for accounting firms, but it also exposes broader operational capabilities such as task querying and arbitrary media upload. This expands the skill's effective permission surface beyond the advertised purpose, increasing the chance of misuse, unintended data handling, or invocation as a generic AI-Hive client rather than a narrowly scoped marketing tool.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The code can query user account information and wallet balance, which is unrelated to generating marketing images for accounting firms. Exposing account metadata in a purpose-specific skill creates unnecessary access to sensitive business information and can leak billing or identity details if the skill is invoked in an untrusted workflow.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill enables implicit invocation without any trigger constraints, so it may activate in broader contexts than intended and handle requests the user did not explicitly mean to route to this accounting-marketing skill. Because this skill is scoped to professional services marketing and AI-HIVE task orchestration, ambiguous activation can cause unintended disclosure of business-sensitive prompts, incorrect task execution, or user confusion about which agent is acting.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.