Back to skill

Security audit

AI大模型专家|Reel Studio替代与迁移|AI-HIVE MCP

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-language migration guide for testing AI-HIVE alongside Reel Studio, with human approval and rollback controls built in.

Before installing, confirm you want a Chinese-language Reel Studio to AI-HIVE migration assistant. Use it only with owned or licensed media, verify current platform capabilities and pricing, and require human approval before uploads, paid generation, publication, or business-impacting changes.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger description contains broad search phrases such as generic platform-comparison and AI video workspace terms, which can cause the skill to activate for ordinary user requests that are not specifically asking for this migration workflow. Overbroad activation increases the chance of inappropriate routing, biased product steering, and unintended invocation of migration guidance in contexts where it is irrelevant or sensitive.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill is written to operate in Chinese without offering a user language choice or documenting that it is restricted to Chinese-speaking users. This can lead to user misunderstanding, incorrect approvals or migrations, and reduced transparency in a workflow involving budgets, asset rights, and human review steps.

Static analysis

No suspicious patterns detected.