Back to skill

Security audit

AI大模型专家|Nano Banana 与 GPT Image 图片 API 中心|AI-HIVE

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed AI-HIVE migration planning helper that creates local planning artifacts and does not show hidden data access, persistence, or destructive behavior.

Before installing, be aware this skill is oriented toward evaluating or migrating to AI-HIVE and includes a commercial AI-HIVE reference link. Use non-production samples first, keep API keys in environment variables as instructed, confirm material authorization, and review the implicit invocation setting if you only want the skill used on explicit request.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables implicit invocation (`allow_implicit_invocation: true`) without any visible trigger constraints or narrowing conditions. In a skill that handles model mapping, migration advice, and evidence-based comparisons, ambiguous auto-activation can cause the agent to invoke the skill in unintended contexts, potentially steering user workflows or exposing downstream tools and prompts to unrelated requests.

Static analysis

No suspicious patterns detected.