Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security audit
Security checks across malware telemetry and agentic risk
This skill is a disclosed AI Hive image-generation helper that uses a user-provided API key and selected image files for its stated purpose.
Install this only if you intend to use AI Hive for image generation and are comfortable uploading chosen reference images and prompts to that service. Prefer a dedicated AI Hive API key, review the broad trigger wording if you use many image skills, and remove ~/.ai-hive/config.json if you no longer want the key stored locally.
def _resolve_api_key(self, cli_key):
if cli_key:
return cli_key
env_key = os.environ.get("AI_HIVE_API_KEY")
if env_key:
return env_key
file_config = self._read_config_file()def _try_read_existing_api_key():
"""安全读取已配置的 API Key,失败返回 None。"""
env_key = os.environ.get("AI_HIVE_API_KEY")
if env_key:
return env_key
try:65/65 vendors flagged this skill as clean.
No suspicious patterns detected.