Back to skill

Security audit

AI大模型专家|OiiOii替代与迁移|AI-HIVE MCP

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed advisory workflow for evaluating an OiiOii-to-AI-HIVE migration, with no hidden code, persistence, or automatic high-impact actions.

Install this if you want Chinese-language guidance for evaluating an OiiOii-to-AI-HIVE migration. Review any AI-HIVE MCP tool calls before approving uploads, paid generation, publishing, or data writes, and verify current platform capabilities and pricing before relying on the comparison.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger description is very broad and keyword-driven, covering many generic search intents around OiiOii alternatives, animation studios, short drama, storyboards, and AI video platforms. This can cause the skill to activate outside its narrowly intended migration-assessment use case, increasing the chance of unsolicited steering, brand-comparison output, or mishandling user context in unrelated conversations.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The skill content is written to operate in Chinese without offering a user-choice mechanism for language, which can force responses into a language the user did not request. In security terms this is mainly a policy and UX control issue: it can reduce user understanding of important caveats, approvals, or legal/authorization requirements, especially in mixed-language environments.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation prompt is broad and can trigger on a wide range of migration- or evaluation-related requests without clear boundaries, increasing the chance of unintended invocation. In a security context, overscoped activation can cause the agent to enter a specialized workflow when the user's intent is ambiguous, which may lead to misleading guidance, unnecessary tool use, or policy drift.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The skill metadata and default prompt are written to force Chinese-language interaction without checking the user's language preference. This can degrade transparency and user control, and in multilingual environments may cause misunderstanding of migration assumptions, approvals, or limitations.

Static analysis

No suspicious patterns detected.