Back to skill

Security audit

Seedream 5.0 Lite 图片生成与编辑

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Seedream image-generation skill, but it uploads chosen images to AI Hive and stores an API key locally.

Install only if you are comfortable sending prompts and any referenced images to AI Hive or its storage backend. Avoid using sensitive personal, confidential, or unreleased brand assets unless AI Hive's data handling terms meet your needs, and keep the stored API key protected because it can authorize account usage and paid generation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill exposes shell, network, file read/write, and environment capabilities while declaring no permissions, which prevents users and reviewers from understanding its true execution scope. In this context, the documentation explicitly installs packages, uploads local images, submits remote jobs, and downloads outputs, so the missing declaration meaningfully weakens consent and review boundaries.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
The skill is presented as a narrow Seedream 5.0 Lite image workflow, but the underlying behavior reportedly includes general AI Hive chat, video generation, account and wallet queries, and model catalog operations. That mismatch is dangerous because users may authorize a specialized image tool while actually granting a broader remote-control interface to other services and account-linked functions.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The activation text is broad enough to match many ordinary image-related requests, increasing the chance the skill runs when the user did not specifically intend to use this external service. Because the skill can upload files and perform networked generation tasks, overbroad triggering raises the risk of unintended data transfer and tool invocation.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The documentation says the skill will automatically upload source materials, submit tasks, and download results, but it does not clearly warn users about remote data transfer, retention, or third-party processing. In an image workflow, this can expose sensitive photos, product assets, branding materials, or personal images to external infrastructure without informed consent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.