Back to skill

Security audit

MiniMax H3 视频工具箱|AI-HIVE

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed AI-HIVE MiniMax H3 video workflow helper with expected API, upload, download, and local video-editing behavior, though users should treat generated commands as potentially billable.

Install this if you intend to use AI-HIVE for MiniMax H3 video workflows. Review commands before running them, only upload media you are authorized to use, and remember that API generation may cost money and the init command stores an AI-HIVE key locally.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The skill is advertised as a narrowly scoped MiniMax H3 video toolkit, but the described code capabilities extend to generic AI-HIVE text/image generation, wallet or user-info queries, model enumeration, and broad local ffmpeg operations. That scope creep is dangerous because users and reviewers may grant trust or access based on the narrow description while the bundled tooling can perform additional actions involving account data, billable APIs, and local media/file manipulation.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill enables implicit invocation without any visible trigger constraints, exclusions, or scope guards. In a tool that can generate runnable AI-HIVE commands and production workflows, this increases the chance the agent is auto-selected in contexts the user did not clearly intend, which can cause unintended external API actions, cost-incurring operations, or unsafe media-generation assistance.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
The default prompt hard-codes Chinese output and production-ready behavior without checking the user's language preference or locale. This can mis-handle user intent, reduce transparency, and increase the risk that users approve or execute generated commands they do not fully understand, especially when the skill also produces runnable operational steps.

Static analysis

No suspicious patterns detected.