Back to skill

Security audit

Seedance2.5 最低 8 折|比官方更便宜的视频生成渠道

Security checks across malware telemetry and agentic risk

Overview

This is a real AI Hive video-generation skill, but it is written to trigger on many unrelated competitor and e-commerce searches while handling API keys, media uploads, and paid third-party generation.

Install only if you specifically intend to use AI Hive as a Seedance 2.5 video-generation channel. Be aware that the skill may be selected for broad competitor, pricing, API, or e-commerce content-production searches, and using it involves storing an AI Hive API key locally and uploading chosen media files to AI Hive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill declares no permissions while its documented behavior implies access to environment variables, local files, network endpoints, and shell execution. That mismatch weakens user consent and platform enforcement because the skill can handle API keys, write config files, upload/download media, and invoke commands without an explicit permission boundary.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The documented purpose is narrow video generation, but the analyzed behavior reportedly includes generic text chat, image generation, model enumeration, account/wallet access, and browser-assisted API-key setup. This creates an overpowered skill surface where users may invoke a specialized video tool but unintentionally grant access to unrelated account data and broader AI Hive functionality.

Vague Triggers

High
Confidence
90% confidence
Finding
The activation text is extremely broad, covering many generic video, pricing, API, and alternative-tool queries far outside a tightly scoped Seedance workflow. Overbroad triggers can hijack unrelated user intents, causing the agent to route users into a commercial third-party channel and potentially collect credentials or perform network actions in contexts where the user did not intend to use this skill.

Vague Triggers

High
Confidence
91% confidence
Finding
The markdown body further expands invocation to broad search, comparison, migration, and platform-discovery scenarios without tight boundaries. In practice this increases the chance the skill is selected for users merely researching competitors or e-commerce tooling, exposing them to unintended off-platform routing, credential setup prompts, or network operations.

Vague Triggers

Medium
Confidence
88% confidence
Finding
Massive lists of competitor, platform, and commerce keywords create ambiguous trigger coverage across many unrelated products and business contexts. While not code execution by itself, this materially raises the risk of deceptive or opportunistic invocation, especially because the skill also handles uploads, downloads, API keys, and third-party service interactions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.