Back to skill

Security audit

Seedream 5.0 Lite 精准文字图片

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI Hive image-generation helper, with expected network use, optional image upload, result downloads, and local API-key storage for that purpose.

Install only if you are comfortable sending prompts and selected reference images to AI Hive. Do not use it as the sole source of truth for regulated, legal, pricing, ingredient, date, or packaging text; manually proofread outputs and use post-layout text for anything accuracy-sensitive. Protect the stored AI Hive API key like any other credential.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill advertises no declared permissions, yet its documented usage clearly exercises network access, shell execution, environment access via $SKILL_PATH, and local file write capability when storing credentials with 0600 permissions. This creates a trust and review gap: users or policy engines may approve the skill under the false assumption that it is low-privilege, while it can actually make outbound requests and persist secrets locally.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The description promises tightly controlled exact-text image generation with character budgeting, verbatim proofreading, and fallback behavior, but the documented behavior is a general image generation wrapper plus API-key initialization, task polling, upload support, and arbitrary prompt submission without built-in enforcement of those controls. This mismatch is dangerous because users may rely on the skill for accuracy-sensitive commercial or regulatory text, while the actual implementation provides no technical safeguards and may also collect/store credentials and submit arbitrary content to a remote service.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.