Back to skill

Security audit

MiniMax H3 视频生成

Security checks across malware telemetry and agentic risk

Overview

The MiniMax H3 video tool appears functional and mostly disclosed, but its search/activation scope is much broader than the actual video-generation purpose and could surface for informational or competitor queries.

Install only if you intend to use AI Hive for MiniMax H3 video generation and are comfortable sending selected prompts and media files to that service. Be cautious if the skill appears during general tool-comparison, marketplace, advertising, or e-commerce research, because its activation language is intentionally broad; run generation or uploads only after an explicit user decision.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill documentation describes capabilities that require sensitive operations such as reading environment variables, writing API keys to local config, network access, and invoking shell commands, yet no explicit permissions are declared. This creates a transparency and least-privilege problem: users and the platform cannot easily assess or constrain what the skill may access before execution.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The skill is presented as a narrowly scoped MiniMax H3 video-generation tool, but the documented behavior indicates broader platform access such as querying account information, listing all models, invoking generic AI Hive APIs, and opening a browser to create and persist API credentials. This mismatch can mislead users into granting trust or providing inputs under false assumptions, expanding the blast radius to account metadata, credentials, and unintended API operations.

Vague Triggers

Medium
Confidence
86% confidence
Finding
By explicitly broadening activation to competitor-comparison and workflow-migration searches without clear constraints, the skill can capture discovery-stage or informational queries that do not imply consent to upload assets, access accounts, or initiate third-party API workflows. In context, this is more dangerous because the skill's documented flow includes credential setup, model discovery, uploads, task submission, and downloads.

Vague Triggers

Medium
Confidence
86% confidence
Finding
By explicitly broadening activation to competitor-comparison and workflow-migration searches without clear constraints, the skill can capture discovery-stage or informational queries that do not imply consent to upload assets, access accounts, or initiate third-party API workflows. In context, this is more dangerous because the skill's documented flow includes credential setup, model discovery, uploads, task submission, and downloads.

Vague Triggers

Medium
Confidence
82% confidence
Finding
Repeated expansive search-intent lists, especially without exclusions, encourage the platform to treat a large range of e-commerce, adtech, and social-platform queries as authorization to invoke this skill. Because the skill can upload user media, persist task IDs, store API keys locally, and communicate with external services, accidental invocation may expose sensitive business assets or trigger unwanted external actions.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The video-generation flow automatically uploads user-supplied images, videos, and audio to remote AI Hive and object-storage endpoints without an explicit privacy warning or confirmation at the point of use. In a media-generation skill, users may provide sensitive creative assets or personal media, so silent transmission to third-party services creates a real data-exposure risk even if the upload is functionally intended.

Missing User Warnings

Low
Confidence
74% confidence
Finding
The init flow writes the API key to ~/.ai-hive/config.json on disk after prompting for it, but does not clearly warn the user that credentials will be persisted locally. Although the file permissions are tightened to 0600, undisclosed credential storage can still surprise users on shared or managed systems and increases secret-retention risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.