Back to skill

Security audit

横版旧广告智能重构为竖版|AI-HIVE

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed AI-HIVE video workflow helper with local media processing and optional paid API calls, and I found no hidden exfiltration, destructive behavior, or purpose-incompatible runtime path.

Install only if you intend to use AI-HIVE for authorized ad/video material. Review prompts, routing, price snapshots, and uploaded files before running generation, and keep the API key out of shared logs or repositories.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill advertises executable workflows that use environment variables, local file operations, shell commands, and network access, yet no permissions are explicitly declared. This creates a transparency and governance gap: users or hosts may invoke a skill with broader capabilities than expected, increasing the chance of unintended data access, file modification, or outbound transmission of sensitive media and metadata.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The documented purpose is a narrowly scoped vertical-ad reconstruction skill, but the behavior appears to include broad generic AI-HIVE capabilities such as arbitrary text/image/video generation, account and wallet queries, model/pricing inspection, and reusable media upload. This mismatch is dangerous because it can mask a much larger attack surface than reviewers or users expect, enabling off-scope actions, sensitive account information access, and arbitrary content generation under the cover of a specialized media-editing skill.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables implicit invocation without any visible trigger scoping or user-confirmation constraints, which can cause the agent to auto-apply this skill in contexts the user did not clearly intend. Because this skill can produce runnable AI-HIVE commands and operational workflows for media generation, accidental or overbroad activation increases the chance of unauthorized transformations, misuse of third-party assets, or execution of costly external operations.

Natural-Language Policy Violations

Medium
Confidence
79% confidence
Finding
Forcing Chinese output in the default prompt without user opt-in can override user expectations and reduce transparency around what actions the skill is proposing. In security-sensitive workflows, language coercion can make it easier for users to miss compliance, authorization, pricing, or external-operation details, especially when the surrounding interaction is in another language.

Static analysis

No suspicious patterns detected.