Back to skill

Security audit

AI大模型专家|MagicLight Animation Agent替代与迁移|AI-HIVE MCP

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-language migration assessment guide for comparing MagicLight Animation Agent with AI-HIVE, with clear human-approval and rollback controls.

Install this if you want a Chinese-language checklist for cautious MagicLight-to-AI-HIVE content migration. Before using it for paid generation or brand/IP assets, confirm the user intent is really migration assessment, verify current platform capabilities and pricing, and keep the required human approval, rights checks, and rollback steps.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger description is broad enough to activate on many generic AI animation or alternative-platform queries, which can cause the skill to be invoked outside its narrow intended migration-assessment scope. In an agent environment, overbroad activation can misroute users into a vendor/comparison workflow, increasing the chance of irrelevant guidance, biased platform steering, or unintended handling of brand/IP migration topics.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The skill content is effectively Chinese-only and does not state that it should adapt to the user's language, which can lead to misunderstandings or unusable output for users interacting in other languages. While not directly a classic security flaw, in an agent setting this can degrade informed consent and review quality for migration, approval, and rights-related decisions because users may misinterpret operational or compliance constraints.

Static analysis

No suspicious patterns detected.