Back to skill

Security audit

AI大模型专家|AI公司AI图片视频营销

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed AI-HIVE marketing helper whose network use, media upload, API key setup, and local outputs fit its stated purpose.

Install only if you intend to use AI-HIVE for marketing asset generation. Treat any referenced media as uploaded to AI-HIVE/object storage, use only authorized materials, confirm budget and routing before generation, and store the API key carefully in an environment variable or the chmod-0600 config file.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill embeds executable shell commands and describes use of environment variables, local file paths, networked API access, and file read/write workflows, yet no permissions are declared. This creates a transparency and policy-enforcement gap: an agent or reviewer may underestimate the skill's operational reach, increasing the chance of unsafe execution, secret exposure, or unreviewed external calls.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill enables implicit invocation while its description covers a very broad set of topics including AI companies, image generation, video generation, marketing, ads, and AI-HIVE operations. This makes it easier for the agent to activate the skill in loosely related contexts without clear user intent, which can unexpectedly trigger external workflow behavior such as querying models, saving snapshots, uploading reference materials, or recording task identifiers.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill uploads user-selected media to AI Hive and object storage endpoints, but the CLI flow does not provide an explicit privacy or data-transfer warning before transmission. In this skill context, users may upload proprietary marketing assets, customer media, or internal reference materials, so silent remote transmission increases the risk of accidental disclosure to third-party services.

Static analysis

No suspicious patterns detected.