Back to skill

Security audit

AI大模型专家|MkBoard替代与迁移|AI-HIVE MCP

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-language workflow for assessing a partial MkBoard-to-AI-HIVE migration and does not contain hidden execution, persistence, or data-exfiltration behavior.

Install this if you want a Chinese workflow for evaluating a controlled, partial migration from MkBoard-style storyboarding into AI-HIVE MCP. Before using it with real projects, confirm AI-HIVE pricing and model availability, upload only assets you own or are licensed to use, and keep the required human approval and rollback steps in place.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger description includes broad product-category and generic search phrases such as 'B-roll', '口播视频', and 'AI视频Agent', which can cause the skill to activate outside its narrowly intended MkBoard migration-assessment use case. Over-broad invocation increases the chance that users are routed into this opinionated workflow when they wanted general advice, creating misleading outputs, inappropriate tool usage, or policy-bypassing context carryover.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The skill content is entirely Chinese-centric and does not offer user language choice or document a hard locale requirement, which can cause users in other languages to receive inaccessible or misunderstood guidance. In a migration-assessment skill, misunderstanding around approvals, copyright, costs, and rollback procedures can materially degrade safe operation even if this is not a direct code-execution issue.

Static analysis

No suspicious patterns detected.