Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
The skill is a disclosed AI image-generation helper that uses an AI Hive API key and user-selected images, with no hidden or destructive behavior found.
Install only if you are comfortable using AI Hive for this workflow. Prompts and any reference images you choose are sent to the service or its upload storage, and the tool may store an API key in ~/.ai-hive/config.json with restricted permissions.
def _resolve_api_key(self, cli_key):
if cli_key:
return cli_key
env_key = os.environ.get("AI_HIVE_API_KEY")
if env_key:
return env_key
file_config = self._read_config_file()def _try_read_existing_api_key():
"""安全读取已配置的 API Key,失败返回 None。"""
env_key = os.environ.get("AI_HIVE_API_KEY")
if env_key:
return env_key
try:63/63 vendors flagged this skill as clean.
No suspicious patterns detected.