Back to skill

Security audit

视频号爆款短视频拆解|AI-HIVE

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed AI-HIVE video workflow helper with expected API use, media upload, local editing, and billing risk, but no artifact-backed deception or unsafe automatic behavior was found.

Install only if you are comfortable using AI-HIVE with your own API key. Treat media uploads as external sharing, confirm paid generation parameters before running them, keep API keys out of logs and repositories, and use only reference videos or brand assets you have rights to use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill advertises executable workflows that use environment variables, local file access, shell commands, and network calls, but it does not declare any permissions or capability boundaries. This creates a transparency and trust problem: users and hosts may invoke the skill expecting a documentation-only teardown helper while it can actually access sensitive runtime resources and perform billable external actions.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The documented purpose is a narrowly scoped 视频号爆款拆解 skill, but the described/code-backed behavior expands into generic AI-HIVE chat, model discovery, media upload, wallet/user-info access, broad video generation, and ffmpeg editing. This mismatch is dangerous because users may authorize or run the skill under false assumptions, enabling unnecessary data exposure, unintended external uploads, account metadata access, and potentially costly or policy-violating operations unrelated to the stated task.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The file is presented as a specialized 视频号爆款拆解/video-decomposition skill, but the implementation exposes a broad AI utility surface including chat, image generation, model enumeration, uploads, and account queries. This expands the skill’s effective permissions and use cases beyond user expectations, increasing the risk of misuse, policy bypass, or accidental invocation of unrelated capabilities.

Context-Inappropriate Capability

Low
Confidence
84% confidence
Finding
Exposing user-info and wallet/balance inspection is unnecessary for a video-decomposition skill and leaks extra account metadata if invoked. While not directly a code-execution issue, it creates avoidable data exposure and violates least-privilege expectations for a narrowly scoped skill.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The generic text-chat endpoint allows the skill to be used for arbitrary model interaction unrelated to the declared decomposition workflow. In a skill ecosystem, this broadens the operational scope and can be used to bypass product-level restrictions or repurpose the skill as a general AI proxy.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
Standalone image generation is unrelated to the stated purpose of decomposing authorized reference videos into reusable structure. This hidden extra capability increases misuse potential and makes the skill materially more powerful than its manifest suggests.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.