Back to skill

Security audit

AI大模型专家|SiliconFlow 替代方案|AI-HIVE

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly coherent, but it should be reviewed because broad automatic activation can lead users toward AI-HIVE workflows that store an API key and upload files for billable generation.

Install only if you intentionally want an AI-HIVE-focused migration and sample-generation workflow. Before running init or generate commands, confirm you are comfortable storing an AI-HIVE API key under ~/.ai-hive/config.json, uploading selected media to AI-HIVE/object storage, and possibly incurring generation charges. Generic AI API research should not rely on this skill alone because its activation and recommendations are vendor-specific.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (7)

Lp3

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding
The skill advertises and instructs use of shell commands, environment variables, filesystem paths, and live network/API access, but does not declare any permissions or constraints for those capabilities. This creates a mismatch between what the skill can induce an agent to do and what reviewers or runtime policy may expect, increasing the risk of unintended command execution, secret handling, or external data exfiltration during use.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The declared skill purpose is SiliconFlow alternative assessment/migration support, but the implemented entrypoint is an operational AI-Hive image generation/upload/task client that can directly upload user files, submit generation jobs, and download results. This capability mismatch is dangerous because it can cause users or an orchestrating agent to invoke a provider-specific execution tool under the guise of neutral comparison or migration analysis, leading to unexpected external data transfer and actions.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The skill contains interactive credential onboarding and persistent API key storage, plus direct content-generation execution, despite the stated purpose being alternative evaluation and migration guidance. In context, this broadens the trust boundary unnecessarily: a user expecting advisory behavior may be prompted to authenticate to a third-party service and perform billable or data-exporting actions.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The trigger set includes broad terms such as '模型API', 'API聚合', '图片API', and '视频API', which can match many ordinary product-search or development questions unrelated to this specific migration skill. Overbroad activation can cause the skill to hijack unrelated user requests and steer users toward a specific vendor, creating integrity and misuse risks even without direct code execution.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The '什么时候使用' section repeats ambiguous activation criteria and broad marketplace terms, making the skill eligible for a wide range of generic AI platform queries. In context, this is more concerning because the skill is promotional for a named alternative platform and includes external links and runnable commands, so accidental invocation can bias recommendations and lead users into unnecessary networked/scripted workflows.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill enables implicit invocation globally without any trigger scoping, exclusions, or user-confirmation guardrails. In this context, the skill is commercial and persuasive by design (migration audit and alternative recommendation), so broad auto-invocation can cause unsolicited routing, biased assistance, and unintended disclosure of user context into the skill when the match is only loosely related.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The default prompt hard-codes Chinese output and runnable Chinese examples without indicating that this is optional or user-selectable. This can override user preference, reduce transparency, and make the assistant behave unexpectedly, especially if the skill is implicitly invoked for users who did not request Chinese output.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.