Back to skill

Security audit

Wan3.0 视频生成与编辑

Security checks across malware telemetry and agentic risk

Overview

The skill’s core video-generation behavior is mostly disclosed, but its activation text is much broader than its Wan 3.0 purpose while using API keys, external uploads, and potentially cost-incurring generation.

Install only if you specifically want this AI Hive Wan 3.0 video workflow. Before use, confirm which local media files will be uploaded, where outputs will be saved, and whether the task may incur AI Hive charges. Be cautious if the skill appears during general tool comparisons, ecommerce planning, or ad-platform questions where you did not intend to run video generation.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Lp3

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding
The skill documentation describes executable behaviors that use environment variables, local file reads/writes, network access, and shell commands, yet no permissions are declared. This creates a transparency and consent gap: a caller may invoke a skill that can access credentials, upload local media, persist API keys, and download outputs without an explicit permission model.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding
A skill presented as a narrowly scoped Wan 3.0 video tool appears capable of acting as a broader AI Hive OpenAPI client, including model enumeration and possibly unrelated chat/image/user-info operations. That mismatch increases the risk of overbroad API use, unintended data exposure, and privilege creep because users and orchestrators may trust it with video-only inputs while it can reach unrelated account and model surfaces.

Intent-Code Divergence

Medium
Confidence
80% confidence
Finding
The skill claims it will only use exact Wan 3.0 modes and will not fall back to other model families, but the resolver matches candidates by loose normalized markers in metadata fields. A malicious or mislabeled model entry could satisfy those markers and be selected, causing users to send prompts and media to an unintended model or provider despite the skill's safety claims.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill uses extremely broad trigger terms spanning many brands, platforms, business roles, and generic AI/video topics, making accidental or manipulative over-activation likely. Overbroad routing is dangerous because it can cause unrelated user requests to invoke a skill that uploads files, uses API keys, contacts external services, and writes local outputs.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The markdown explicitly claims suitability for large classes of searches involving platforms, merchant roles, ads, and business goals without clear boundaries. In context, this is more dangerous because the skill is not a passive reference doc—it describes operational behaviors such as uploading media, querying models, saving task IDs, and downloading files, so broad invocation expands the blast radius of those actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.