Back to skill

Security audit

AI大模型专家|LovAgents替代与迁移|AI-HIVE MCP

Security checks for vulnerabilities and agentic risk

Overview

This skill provides a disclosed LovAgents-to-AI-HIVE migration assessment workflow with manual approval and rollback controls, and it does not include hidden execution code.

Install this only if you want help evaluating a partial LovAgents-to-AI-HIVE media workflow. Before using it, confirm current product capabilities and pricing, use only assets you own or are licensed to upload, and keep the required budget approval and human review steps in place.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list is broad and keyword-heavy, covering generic terms like '无限画布', '多模态Agent', and 'AI视频Agent' that can match many unrelated user requests. This can cause the skill to activate outside its intended migration-assessment scope, increasing the chance of irrelevant guidance, biased vendor steering, or unsafe handling of comparative business claims.

Static analysis

No suspicious patterns detected.