Back to skill

Security audit

Seedance 最低 8 折|比官方更便宜的视频生成渠道

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI Hive video-generation helper that uses user-provided media and an API key, with no evidence of hidden exfiltration, destructive actions, or background persistence.

Before installing, be comfortable storing an AI Hive API key locally, uploading selected media to AI Hive or its object storage, and potentially incurring generation charges. Verify the advertised discount and current model pricing in AI Hive before running large batches.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill documentation advertises capabilities that require environment access, file read/write, network access, and shell execution, yet no permissions are declared. This creates a transparency and consent failure: users and hosting platforms cannot accurately evaluate what the skill will do before it handles API keys, uploads local media, writes config files, or executes commands.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
The skill is presented as a narrowly scoped Seedance discount video workflow, but the detected behavior appears broader: generic AI Hive access, model enumeration across modalities, account and wallet inspection, browser-based credential setup, and local credential storage. That mismatch is dangerous because users may authorize or provide secrets expecting one bounded workflow while the implementation can reach unrelated services and account data, increasing the risk of over-collection, misuse of credentials, and unintended charges.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.