Back to skill

Security audit

爆款视频镜头节奏拆解|AI-HIVE

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed AI-HIVE video workflow helper that uses expected API calls, media uploads, local outputs, and ffmpeg commands for its stated purpose.

Install only if you intend to use AI-HIVE for video workflows. Review commands before running them, use only media you are authorized to upload, confirm any billable generation step, and avoid placing real API keys in logs, screenshots, or shared repositories.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill embeds executable examples and operational guidance that use environment variables, local files, shell commands, networking, and media tooling, yet it declares no permissions or capability boundaries. This creates a transparency and least-privilege problem: users or hosting platforms may invoke a skill believing it is documentation-only or low-risk, while it can drive API calls, process local media, and potentially expose sensitive files or credentials through surrounding tooling.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
The documented purpose is a shot-rhythm analysis and recut assistant, but the behavior described extends into broad AI chat, media generation, account/wallet access, model/pricing discovery, and direct ffmpeg editing. This mismatch is dangerous because it expands the attack surface far beyond user expectations: a user authorizing timeline analysis may inadvertently enable generic remote API use, local media manipulation, billing-related actions, or access to account information.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The skill metadata is broad enough to permit implicit invocation for loosely related requests, while the default prompt pushes the agent toward producing runnable workflows and commands. In a skill that can drive external API operations and media-processing workflows, weak trigger boundaries increase the chance of unintended activation and overbroad automation beyond what the user explicitly requested.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
Forcing Chinese output without user opt-in can override user expectations and reduce transparency around generated workflows, commands, and safety-relevant details. In this context, the skill may generate operational instructions for external services, so unwanted language forcing can cause misunderstanding, misuse, or failure to notice risky steps.

Static analysis

No suspicious patterns detected.