Back to skill

Security audit

静态海报动态化|AI-HIVE

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed AI-HIVE poster-to-video workflow with expected API use, local media handling, and ffmpeg helpers, with no artifact-backed deception or hidden destructive behavior found.

Install only if you intend to use AI-HIVE for poster-to-video generation. Expect it to upload user-selected media to AI-HIVE, use an API key, potentially incur generation costs after confirmation, store an API key locally if you run init, and write generated files to the configured output directory.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill advertises executable workflows that use environment variables, local file access, shell commands, and outbound network requests, but it declares no permissions or trust boundaries. This creates a capability transparency gap: an operator may invoke the skill expecting only planning/output generation while the embedded workflow can access sensitive local resources and external services, increasing the chance of unintended data exposure or execution in overly permissive environments.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The documented purpose is a narrowly scoped poster-to-motion workflow, but the detected behaviors include broader account inspection, arbitrary model enumeration, generic chat/image generation, and general ffmpeg operations. That mismatch is dangerous because users and reviewers may grant trust or permissions for a limited media workflow while the skill can perform materially broader actions, including exposing account metadata, incurring unexpected costs, or processing unrelated user files.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation without any trigger constraints, so the agent may auto-activate this capability in contexts where the user did not clearly request poster-to-video generation or AI-HIVE API operations. Because this skill can produce runnable commands and interact with external generation workflows, broad auto-invocation increases the chance of unintended tool use, scope creep, and accidental processing of unauthorized or policy-sensitive media requests.

Static analysis

No suspicious patterns detected.