Back to skill

Security audit

小红书爆款视频拆解|AI-HIVE

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Xiaohongshu marketing video workflow that uses AI-HIVE for user-directed media generation, with expected credential, upload, download, and local video-editing behavior disclosed enough for installation with normal caution.

Install this only if you are comfortable using AI-HIVE for selected marketing media. Do not provide unauthorized reference videos, real customer claims, or private media you cannot upload to a third-party service, and review prompts, routing mode, price snapshot, and output directory before running generation commands.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill exposes operational capabilities including environment access, filesystem read/write, network calls, and shell execution, yet it declares no permissions. This creates a transparency and containment problem: users and hosting systems cannot accurately assess what the skill may access or execute, increasing the chance of unintended secret exposure, local file access, or arbitrary command execution through supporting scripts.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The documented purpose is narrow, but the described behavior includes broader capabilities such as generic AI chat, image generation, browser-based API key initialization with local credential storage, and ffmpeg-based media manipulation. This mismatch is dangerous because it can mask materially riskier behavior than users expect, including credential handling, external network use, and local media/file processing that could be abused or trigger privacy, cost, or integrity issues.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The manifest allows implicit invocation for a broadly scoped marketing/content-generation skill without narrow trigger conditions or exclusions. This increases the chance the skill is auto-selected in contexts the user did not clearly intend, causing unintended workflow execution, third-party API usage, or content generation in sensitive scenarios such as unauthorized imitation or deceptive marketing.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The default prompt forces Chinese output regardless of user preference, which can override user intent and reduce transparency about how the assistant will respond. While not directly enabling code execution or data exfiltration, it can cause misleading UX, compliance issues in multilingual environments, and accidental misuse if users cannot review generated marketing workflows accurately.

Static analysis

No suspicious patterns detected.