Back to skill

Security audit

商品素材库自动混剪|AI-HIVE

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed AI-HIVE product-video workflow, with normal risks around API keys, paid generation, and uploading user-selected media.

Install only if you are comfortable giving AI-HIVE an API key and uploading selected product media to that service. Review prompts, routing, cost implications, and output paths before running generation, and avoid using unlicensed media or real claims that have not been verified.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill exposes code-capable behavior including environment access, file read/write, shell execution, and network use, but does not declare permissions or clearly scope those capabilities. This is dangerous because callers and reviewers cannot accurately assess what the skill may access or modify, increasing the risk of unintended data exposure, filesystem changes, command execution, or outbound transfer of sensitive material such as local media and API credentials.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding
The documented purpose is narrowly framed as SKU-aware product montage, but the behavior reportedly includes generic chat, generic image generation, account/model querying, browser-based API key initialization with local config storage, and standalone ffmpeg operations outside that scope. This mismatch is dangerous because it creates hidden or under-disclosed functionality that can be abused for broader data access, credential handling, or unintended external API usage, especially when users trust the skill to perform only a constrained workflow.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables implicit invocation with no trigger constraints, exclusions, or scoped guardrails, so it may auto-activate in contexts where the user did not clearly request this capability. Because the skill can produce runnable workflows and AI-HIVE commands for media generation pipelines, unexpected invocation increases the chance of unauthorized, policy-violating, or contextually inappropriate automation.

Static analysis

No suspicious patterns detected.