Back to skill

Security audit

美图 MOKI 视频生成替代|AI 视频生成与编辑

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI video-generation API helper that uploads user-selected media and stores an API key locally, with no evidence of hidden or destructive behavior.

Before installing, understand that prompts and any media files you provide may be uploaded to AI Hive or its storage flow, and that an AI Hive API key can be stored locally. Use only approved assets and credentials you are comfortable using with that service.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill advertises and demonstrates shell execution, file access, environment use, and outbound network calls, yet declares no permissions. This creates a transparency and policy-enforcement gap: users or the hosting platform may not realize the skill can read local inputs, write files, and contact a remote API, which increases the risk of unintended data exposure or misuse.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The invocation text is broad and includes generic commercial-video and brand-marketing terms, which can cause the skill to trigger in situations beyond its narrow intended use. Over-triggering is dangerous because it may route unrelated user requests into a skill that performs external API operations and local file handling, increasing the chance of inappropriate execution or data handling.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.