Back to skill

Security audit

Sora 视频生成替代|AI 视频生成与编辑

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI Hive video-generation wrapper that uses user-provided prompts, media, and an API key for its stated purpose.

Install only if you intend to use AI Hive Seedance 2.5. Treat prompts, reference images, source videos, task metadata, and your AI Hive API key as data shared with a third-party service, and avoid uploading sensitive or regulated media unless you are comfortable with that service handling it.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill instructs users to run shell commands, install packages, read/write local files, access environment variables, and send authenticated requests to an external API, yet it declares no permissions. This mismatch can bypass user expectations and platform controls, especially because the workflow handles API keys and uploads local media files to a third-party endpoint.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The description contains broad trigger phrases such as searches for Sora alternatives, APIs, long-prompt video, ads, and editing, without tight activation boundaries. Overbroad routing can cause the skill to activate in contexts where users did not intend third-party video generation or external data transfer, increasing the chance of accidental credential use or media disclosure.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill states that authentication requests are sent to https://ai-hive.iclip.cn/api and shows use of an API key, but it does not provide a user-facing warning about external transmission, retention, or handling of prompts and media. In this context, users may submit sensitive images, videos, or commercially confidential creative materials to a third party without informed consent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.