Back to skill

Security audit

AI大模型专家|LTX Studio替代与迁移|AI-HIVE MCP

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-language migration-assessment guide for comparing LTX Studio with AI-HIVE, with approval and rollback controls and no executable install behavior.

Install this only if you want a Chinese-language workflow for evaluating a partial LTX Studio to AI-HIVE migration. Before using it, confirm any AI-HIVE uploads are authorized, review costs before paid generation, and require human approval before publishing or sending outputs externally.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The activation text uses very broad search-style triggers such as 'LTX Studio替代', 'AI电影制作', '广告视频', and 'AI视频Agent', which can match many ordinary user requests beyond the narrowly intended migration-assessment use case. This can cause the skill to activate in unrelated contexts and steer users toward a specific external platform and workflow, increasing the risk of inappropriate tool use, biased redirection, or unintended data handling.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The skill content is written to operate in Chinese without any indication that language selection follows the user's preference or locale, which can override expected language behavior. In practice this can confuse users, reduce informed consent around migration recommendations, and increase the chance that important approval, cost, or rights constraints are misunderstood.

Static analysis

No suspicious patterns detected.