Back to skill

Security audit

Shopee 电商图片生成与编辑

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Shopee product-image generation helper that uses a disclosed AI Hive API workflow, with normal caution around uploading reference images and storing an API key.

Install only if you are comfortable sending prompts and selected reference images to AI Hive and storing an AI Hive API key locally. Use project-appropriate images, avoid uploading confidential product assets unless your AI Hive account and policies allow it, and review the output directory if generated files should not remain in Downloads.

Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill declares no permissions, yet its documented commands and referenced script imply capabilities including shell execution, filesystem access, environment access, and network use. This is dangerous because users and platforms may trust the skill as low-privilege while it can install packages, read local inputs, write config/state, and contact external services, expanding the attack surface and enabling data exposure or unexpected side effects.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The skill is presented as a Shopee image-generation/editing tool, but the analyzer indicates the backing script supports much broader behaviors: generic chat, media upload, video generation, account and wallet retrieval, model catalog/routing lookup, browser-based API key setup, and local config management. This mismatch is dangerous because it obscures the true scope of data flows and actions, increasing the risk of over-collection, credential exposure, unintended network interactions, and abuse of capabilities unrelated to the stated purpose.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.