Back to skill

Security audit

快手电商图片生成与编辑

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI image-generation helper that uses an API key, network calls, user-selected media uploads, and local result downloads in ways that fit its stated purpose.

Install only if you are comfortable giving this skill an AI Hive API key and uploading selected product, host, or factory reference images to the AI Hive service. Use the documented generate/task/upload/init commands, keep the config file private, and avoid passing sensitive unrelated files as reference media.

Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill exposes or relies on code capabilities including environment access, file read/write, network, and shell execution, yet declares no permissions. This creates a transparency and trust gap: users and orchestrators may invoke it as if it were low-risk documentation, while it can actually execute privileged operations such as installing packages, writing config, and making outbound requests.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
The documented purpose is limited to ecommerce image generation/editing, but the detected behavior includes unrelated and more sensitive capabilities such as chat/text calls, video generation, user/account and wallet queries, model discovery, broad media upload, and browser-based API key setup. This mismatch is dangerous because it can mislead users and policy layers about what the skill may do, increasing the chance of over-privileged execution, unexpected data handling, or credential exposure.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.