Back to skill

Security audit

Seedream 5.0 Lite 种草图片

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Seedream image-generation helper that uses a fixed AI Hive API endpoint, user-selected image uploads, and local API-key setup without hidden or destructive behavior.

Before installing, understand that this skill sends prompts and any images you name to AI Hive, stores an API key locally if you run init, and can download generated outputs to your machine. Use only images you are authorized to upload and review generated marketing claims before publishing.

Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding
The skill declares no permissions, yet its documented behavior includes shell execution, file reads/writes, environment access, and outbound network use. This mismatch weakens review and consent boundaries, making it easier for a caller or operator to invoke capabilities they did not expect, including local credential storage and remote API interaction.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The documented purpose is narrowly framed as compliant Seedream-based recommendation imagery, but the described tooling also supports credential setup, arbitrary task lookup, reusable media upload, and free-form image generation. That gap is dangerous because users and policy systems may trust the narrow description while the underlying commands enable broader data handling and content generation than advertised.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.