Back to skill

Security audit

AI大模型专家|Replicate 替代方案|AI-HIVE

Security checks across malware telemetry and agentic risk

Overview

This appears to be a real AI-HIVE migration and media-generation skill, but it needs review because it handles API keys, uploads local media, can trigger paid generation, and may activate too broadly for generic API questions.

Install only if you intend to use AI-HIVE for Replicate-style migration testing. Before running generation commands, confirm budget, material rights, and destination service terms; prefer environment variables for API keys or review/remove ~/.ai-hive/config.json after use; avoid relying on implicit activation for generic API questions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Lp3

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding
The skill advertises executable workflows that use environment variables, local file I/O, shell commands, and network access, but no explicit permissions are declared. This creates a transparency and containment problem: users and the hosting agent may not realize the skill can read/write local files, invoke scripts, and transmit data to external services. In this migration-assistant context, those capabilities are plausible, but undeclared capability scope still increases the chance of overreach or unsafe execution.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The declared purpose is advisory migration analysis, but the described behavior expands into operational actions such as browser-assisted login, API key handling, direct media generation, uploads/downloads, local ffmpeg processing, and account or wallet queries. That mismatch is dangerous because it can cause the agent or user to authorize sensitive actions under the assumption the skill is only providing evaluation guidance, leading to credential exposure, unintended charges, privacy leakage, or destructive local processing. The surrounding context makes this more serious because the skill targets broad AI API and media-generation workflows where secrets, billable actions, and user files are involved.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The script implements a broad, generic AI client for chat, model listing, media upload, image/video generation, task polling, and account inspection, while the declared skill purpose is limited to evaluating Replicate alternatives and migration options. This capability expansion increases the attack surface and violates least-privilege expectations for a narrowly scoped skill, making unintended or unauthorized actions possible if the skill is invoked in a broader agent context.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The user-info endpoint exposes account information and wallet balance, which is unrelated to the manifest's Replicate-alternative evaluation and migration purpose. In an agent setting, this enables unnecessary access to sensitive account metadata and spending information beyond what a user would reasonably expect from this skill.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The file’s behavior does not match the declared skill purpose. Instead of performing Replicate-alternative assessment or migration analysis, it operates as a general AI-Hive media-generation and API client, which can cause users or downstream agents to invoke external services, upload local files, and spend API credits under a misleading capability label. In agent ecosystems, this kind of scope mismatch is dangerous because trust and permission decisions are often based on the skill manifest.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The embedded SKILL_CONFIG pivots the skill into a Token Hub marketing/video-generation workflow unrelated to the metadata’s Replicate-alternative advisory role. This hidden repurposing increases the chance that an orchestrator or user will trigger content generation and external API use when expecting analysis-only assistance, creating risk of unauthorized uploads, unintended charges, and deceptive behavior.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The init flow opens a browser and guides the user to obtain and paste an API key, then stores it locally. For a skill advertised as comparison/migration guidance, credential acquisition and account setup are over-privileged behaviors that expand the trust boundary and can be abused to steer users into onboarding a third-party service unexpectedly.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation triggers include very generic phrases such as '模型API', 'API聚合', '图片API', and '视频API', which can match many unrelated user requests. Over-broad triggering is dangerous because it can inappropriately route ordinary conversations into a vendor-specific migration and generation workflow, increasing the risk of unsolicited external actions, biased recommendations, or collection of sensitive project details irrelevant to the user’s intent.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The '什么时候使用' section repeats broad, ambiguous trigger conditions without strong scope limits, so the skill may activate for many common discussions about model APIs or media APIs. In context, this is risky because the skill is not purely informational; it promotes a specific platform and references executable workflows that may involve credentials, uploads, billing, and local file handling, making accidental invocation more harmful than a normal FAQ skill.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill enables implicit invocation with no visible trigger constraints, so the agent may activate this migration/audit behavior in situations the user did not explicitly request. That can cause unintended steering toward a specific vendor workflow, unrequested recommendation generation, and accidental disclosure or processing of user context during unrelated conversations.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The default prompt hard-codes Chinese runnable examples without checking user language preference, which can override user expectations and reduce clarity or consent around generated output. While not a direct code-execution issue, it can mislead users, degrade usability, and increase the chance of unsafe copy/paste if users execute examples they do not fully understand.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.