Back to skill

Security audit

Pika 视频生成替代|AI 视频生成与编辑

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent AI video-generation helper that discloses its API use, media uploads, API-key storage, and output downloads.

Before installing, understand that user-selected images or videos will be uploaded to AI Hive, an AI Hive API key may be stored locally, and generated files are downloaded to your machine. Use it only with media you have rights to upload and with an API key you are comfortable using for this service.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill invokes shell commands, reads local files, writes data, accesses environment variables, and makes network requests, yet declares no permissions or capability boundaries. This creates a transparency and policy-enforcement gap: a caller or platform may expose more access than users expect, increasing the chance of unauthorized file access, secret handling, or outbound data transfer to the external API endpoint.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The description contains broad trigger terms such as general short-video generation, product motion graphics, and vertical video creation, which can cause the skill to activate for requests outside the narrow 'Pika alternative/migration' scenario. Overbroad routing can send unrelated user tasks into a networked, file-handling workflow, increasing the chance of unintended data exposure, misuse of external APIs, or execution of capabilities the user did not mean to invoke.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.