Back to skill

Security audit

AI大模型专家|WaveSpeedAI 替代方案|AI-HIVE

Security checks across malware telemetry and agentic risk

Overview

The skill is not malicious, but it needs Review because it can run local and network media workflows, broadly auto-activate, and persist an AI-HIVE API key with imperfect disclosure.

Install only if you specifically want AI-HIVE migration or media-generation testing. Before running commands, confirm costs, use only media you are allowed to upload, and prefer an environment variable for the API key; if you run init, know it stores the key in ~/.ai-hive/config.json. Consider disabling implicit invocation or narrowing triggers so ordinary API or image/video questions are not routed into this vendor-specific workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill advertises executable workflows that use shell, filesystem, environment variables, and network access, yet no explicit permissions are declared. That mismatch reduces transparency and weakens enforcement boundaries, increasing the chance that a caller invokes code with broader capabilities than expected, including handling API keys and local files. In this context the risk is elevated because the skill encourages running local scripts, exporting secrets, and interacting with remote services.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
The documented purpose is migration assessment and comparison guidance, but the skill also exposes a much broader operational surface: generic AI-HIVE API access, media upload/download, local ffmpeg processing, and interactive API-key setup with local storage. This description-behavior mismatch can mislead users and reviewers about the real capabilities, causing them to trust and run a skill that can execute materially more powerful actions than its stated scope suggests. The danger is higher here because those hidden-in-practice capabilities touch secrets, local media, shell commands, and external network calls.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger list contains broad terms like model API, API aggregation, image API, and video API, which are likely to match many unrelated requests. Overbroad activation can cause this skill to be selected in contexts where users did not intend to invoke a migration workflow that promotes a specific vendor and encourages code execution, increasing the chance of inappropriate network, file, or shell activity. The surrounding context makes this more dangerous because the skill is not read-only; misrouting can lead to operational actions and handling of secrets.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The 'when to use' criteria are ambiguous and broad enough to capture generic platform-switching or media-generation requests without clear constraints. This can route ordinary user requests into a skill that steers toward a particular product and provides executable local/remote workflows, creating a risk of unintended actions, data exposure, or biased recommendations outside the user's actual intent. The context increases risk because the skill is effectively both marketing-oriented and operationally capable.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill enables implicit invocation without any trigger constraints, so it may activate on loosely related user requests and inject its migration-focused guidance unexpectedly. Because the skill is oriented around vendor comparison and migration advice, over-broad activation can bias responses, expose users to unintended recommendations, and expand the attack surface for prompt-routing abuse.

Natural-Language Policy Violations

Medium
Confidence
79% confidence
Finding
The default prompt hardcodes runnable Chinese examples, overriding user language preference and potentially causing unexpected output format changes. While not directly a code-execution flaw, forced formatting can reduce user control, create social-engineering opportunities through unsolicited runnable content, and make the skill behave in ways the user did not request.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.