Back to skill

Security audit

可灵 Kling 视频生成替代|AI 视频生成与编辑

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI Hive video-generation helper that sends user-chosen prompts and media to a third-party API.

Install only if you intend to use AI Hive for video generation. Use authorized media only, expect prompts and selected media files to be uploaded to the service, and review AI Hive account costs, terms, and API-key handling before running generation commands.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill advertises and demonstrates shell execution, local file access, environment-variable use via $SKILL_PATH, and outbound network access to a remote API, yet no permissions are explicitly declared. This creates a transparency and governance gap: an agent or reviewer may underestimate the skill's operational reach, increasing the risk of unintended command execution, filesystem access, or data egress when the skill is invoked.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The description contains broad search-style activation phrases such as Kling alternative, 可灵 API, 文生视频, 图生视频, 视频编辑, and short-film production terms, which can match many ordinary user requests without tight boundaries. Over-broad triggering can cause the wrong skill to activate and then expose shell/network/file capabilities in contexts where the user did not specifically intend to run this workflow.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.