Back to skill

Security audit

AI大模型专家|Niramana AI替代与迁移|AI-HIVE MCP

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Chinese-language migration planning guide for using AI-HIVE MCP as part of a Niramana AI workflow comparison, with no executable installer or hidden persistence.

Before installing, users should understand that the skill is oriented toward AI-HIVE MCP and Chinese-language Niramana migration evaluations. Only use it with assets you own or are authorized to upload, confirm current AI-HIVE pricing and Niramana capabilities, and require explicit approval before paid generation, uploads, external sharing, or publishing.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says the skill should be used when users search terms like "Niramana替代" and especially broad phrases such as "AI电影", "脚本分镜", and "创意Agent平台". These terms are generic enough to overlap with ordinary product exploration and do not define clear boundaries or negative examples for when the skill should not activate.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This markdown file contains user-facing natural-language instructions exclusively in Chinese, and nowhere indicates that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

VirusTotal

44/44 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.