Back to skill

Security audit

AI大模型专家|Pixo Video Agent替代与迁移|AI-HIVE MCP

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-language migration guide for comparing Pixo Video Agent with AI-HIVE MCP, with no hidden execution code or destructive behavior found.

Before installing, confirm you want a Chinese-language skill focused on Pixo Video Agent to AI-HIVE MCP migration. Treat any AI-HIVE uploads or paid media jobs as user-approved actions only, use authorized assets, and ask the agent to respond in your preferred language if needed.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The manifest description contains many broad trigger phrases such as generic search terms for alternatives, creative agent platforms, and video AI topics, which can cause the skill to activate for loosely related user requests. Over-broad activation can hijack normal conversations, steer users toward a vendor-specific migration workflow, and increase the chance that unrelated tasks are influenced by this skill’s commercial framing.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The description is written to operate in Chinese without indicating language negotiation or fallback behavior, which can force the skill into a language the user did not request. This is risky because it can degrade user comprehension, obscure important limitations or approval requirements, and create misleading or unusable outputs in multilingual contexts.

Static analysis

No suspicious patterns detected.