Back to skill

Security audit

AI大模型专家|Kie.ai 替代方案|AI-HIVE

Security checks across malware telemetry and agentic risk

Overview

This is mostly a disclosed AI-HIVE migration helper, but it needs Review because broad automatic activation is paired with API-key persistence and media upload workflows.

Install only if you intentionally want AI-HIVE migration and media-generation assistance. Treat API-key setup, uploads, generation calls, and downloads as explicit user-approved actions; avoid using production secrets or sensitive media until you have reviewed AI-HIVE terms, pricing, retention, and revocation controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill advertises executable workflows that use environment variables, local file access, shell commands, and network operations, but it declares no permissions. This creates a transparency and consent problem: a user or host system may invoke a skill that can read/write files, use API keys, and perform external requests without an explicit permission model, increasing the chance of unintended data exposure or unsafe execution.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
The documented purpose frames the skill as an evaluation/migration advisory tool, but the behavior extends into credential acquisition guidance, direct API invocation, media upload/download, local file persistence, and ffmpeg-based processing. That mismatch is dangerous because users and policy controls may treat it as a low-risk comparison skill while it actually performs sensitive operations involving secrets, local assets, external transfers, and executable tooling.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The file is presented as a skill-scoped image generator, but it also contains generic chat, video generation, model enumeration, user-info lookup, media upload, and task polling capabilities. This expands the executable attack surface and violates least-privilege expectations for a narrowly scoped skill, making it easier for a caller or wrapper to invoke unintended networked actions using the same API key.

Vague Triggers

Medium
Confidence
77% confidence
Finding
The trigger list contains broad phrases such as model/API aggregation and media API terms that can match many unrelated conversations. Overbroad activation increases the risk that the skill is invoked outside its intended context, causing unsolicited redirection to a commercial platform, accidental collection of sensitive inputs, or execution of code paths the user did not intend to use.

Vague Triggers

Medium
Confidence
74% confidence
Finding
The when-to-use section uses ambiguous conditions like changing an AI gateway, expanding to image/video generation, or needing task records, which are common needs across many workflows. In context, this broad scope makes the skill more dangerous because it is promotional and operational: it could activate for general production tasks and then steer users into external API use, uploads, downloads, or local processing without a clearly bounded migration scenario.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation without any trigger constraints, so it may activate in broader contexts than intended and influence responses without clear user intent. Because this skill is designed to steer users toward a specific migration/audit workflow around Kie.ai alternatives and AI-HIVE, over-broad activation can cause unsolicited vendor-biased recommendations, unexpected workflow insertion, or prompt-scope confusion.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The default prompt forces runnable Chinese examples regardless of the user's language preference, which can override user intent and reduce clarity or usability. While this is not a direct code-execution issue, it is a prompt-governance weakness that can lead to misleading outputs, poor UX, and unintended disclosure or misunderstanding in multilingual contexts.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.