Back to skill

Security audit

AI大模型专家|多模型成本路由中心|AI-HIVE

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed AI-HIVE routing-evaluation helper with a local planning script and no hidden data access, persistence, or automatic production changes.

Installers should treat this as an advisory migration-planning skill: use non-production samples first, keep provider keys in environment variables, verify current prices and terms on the day of use, and do not expand traffic unless rollback and budget controls are in place.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
`allow_implicit_invocation: true` lets the platform auto-select this skill without an explicit user request or tight trigger boundaries. Because this skill can influence routing, migration, rollback, and comparative recommendations, broad implicit activation increases the chance of unintended execution, prompt hijacking through ambiguous user queries, or application in contexts where the user did not consent to this specialized behavior.

Static analysis

No suspicious patterns detected.