Back to skill

Security audit

AI大模型专家|ScriptFrame替代与迁移|AI-HIVE MCP

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed migration-planning guide for comparing ScriptFrame with AI-HIVE, with user approval controls around uploads, spending, publishing, and rollback.

Before installing, understand that the skill promotes an AI-HIVE-centered migration evaluation workflow. Use it when you actually want to compare or pilot migration from ScriptFrame, and review any asset uploads, paid generation, or publishing steps before approval.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The activation description includes broad trigger phrases such as 'ScriptFrame替代', '多Agent分镜', 'AI视频Agent', and '创意Agent平台', which can match many ordinary user queries beyond the narrow migration-evaluation use case. This can cause the skill to activate in unrelated contexts and steer users into platform-comparison or migration guidance they did not request, increasing the chance of misrouting, biased responses, and accidental disclosure or processing of sensitive project details.

Static analysis

No suspicious patterns detected.