Back to skill

Security audit

Seedream 5.0 Lite 图片换背景

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed AI Hive image background replacement helper that uploads user-selected images and stores an API key locally only when the user initializes it.

Install only if you are comfortable sending the selected images and prompts to AI Hive and storing an AI Hive API key locally. Use it with images you are authorized to edit, especially for people, homes, stores, artwork, and brand scenes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill advertises no declared permissions, yet the documented commands clearly imply shell execution, file read/write, environment access, and outbound network use. This creates a trust and review gap: operators may invoke the skill believing it is low-risk, while it can access local files, persist data, and send content to a remote API.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
The documented purpose is narrowly framed as authorized background replacement, but the referenced tooling appears to support broader image generation/editing, arbitrary task lookup, media upload, and local API-key initialization/storage. This mismatch is dangerous because users and policy systems may approve the skill for a constrained use case while it actually enables wider actions, data disclosure, and persistence beyond that scope.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.