Back to skill

Security audit

TikTok Shop 电商视频生成与编辑

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent AI Hive video-generation helper for TikTok Shop commerce assets, with expected API-key setup, media upload, and output download behavior.

Before installing, understand that this skill sends prompts and any selected product media to AI Hive, stores an API key locally if you run init, and downloads generated outputs to your Downloads folder. Use a dedicated API key and avoid uploading media you are not allowed to share with that service.

Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill exposes broad capabilities including shell, network, file read/write, and environment access without declaring permissions or constraining their use. In an agent ecosystem, this creates a transparency and sandboxing gap: users may invoke what appears to be a simple video-editing skill while it can access local resources, execute commands, and communicate externally.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
The documented purpose is narrowly scoped to TikTok Shop ecommerce video generation, but the detected behavior includes broader AI chat, generic image generation, account and wallet inspection, model enumeration, uploads, and general API configuration. That mismatch is dangerous because it obscures powerful unrelated operations from users and reviewers, increasing the risk of unauthorized data access, billing abuse, or covert exfiltration through apparently benign media workflows.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.