Back to skill

Security audit

三剪客 · Seedance 2.0

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed Seedance video-generation wrapper, but its bundled client can also use the same API key to enumerate and call arbitrary a7w marketplace plugins beyond the stated Seedance scope.

Review this before installing if you only want a narrow Seedance tool. Use a least-privilege a7w API key if available, avoid setting `--host` or `A7W_HOST` unless you trust the endpoint, confirm asset IDs before deletion, and do not include sensitive prompts or media URLs when enabling web search or callback URLs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (22)

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/client.py (reported line 111)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            raw = resp.read().decode("utf-8", "replace")
            status = resp.status
    except urllib.error.HTTPError as exc:

Tainted flow: 'req' from os.environ.get (line 151, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/client.py (reported line 153)May include surrounding context.

python
headers["Content-Type"] = "application/json"
    req = urllib.request.Request(url, data=data, headers=headers, method=method)
    try:
        with urllib.request.urlopen(req, timeout=timeout) as resp:
            raw = resp.read().decode("utf-8", "replace")
            status = resp.status
    except urllib.error.HTTPError as exc:

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is described as a Seedance-specific video-generation wrapper, but the detected behavior is that of a generic API client capable of listing all apps, viewing arbitrary schemas, invoking arbitrary plugin APIs, exporting schemas, and storing API keys locally. That mismatch is dangerous because users and agents may trust the narrower description while actually granting a broad API pivot tool that can enumerate services, access unrelated functionality, and persist secrets on disk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
计费,按分辨率和是否含视频输入分档。支持 创建素材资产组合、上传素材、获取素材详情、更新素材、删除素材、查询任务、创建任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.c

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
计费,按分辨率和是否含视频输入分档。支持 创建素材资产组合、上传素材、获取素材详情、更新素材、删除素材、查询任务、创建任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.c

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire user-facing README is written in Chinese, including setup, usage, and safety instructions, with no indication that other languages are supported or that Chinese is required for a region-specific reason. This creates a natural-language policy concern because it imposes a specific language on users without opt-in or justification.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises executable client usage with network, shell, file, and environment access but does not declare any tool scope or permissions boundaries. In practice this can cause an agent or user to run code with broader capabilities than expected, increasing the chance of unintended network calls, local file access, or credential handling beyond the stated video-generation purpose.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 11)May include surrounding context.

md
name: seedance-video
slug: seedance-video
displayName: 三剪客 · Seedance 2.0
description: "基于火山方舟 Seedance 2.0 的多模态视频生成应用。支持文本/图片/视频/音频任意组合输入,可输出 480p/720p/1080p 分辨率、4~15 秒时长的视频,并可选生成同步音频。按 token 计费,按分辨率和是否含视频输入分档。支持 创建素材资产组合、上传素材、获取素材详情、更新素材、删除素材、查询任务、创建任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.4
summary: "「Seedance 2.0」的完整调用封装:7 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 95)May include surrounding context.

md
name: seedance-video
slug: seedance-video
displayName: 三剪客 · Seedance 2.0
description: "基于火山方舟 Seedance 2.0 的多模态视频生成应用。支持文本/图片/视频/音频任意组合输入,可输出 480p/720p/1080p 分辨率、4~15 秒时长的视频,并可选生成同步音频。按 token 计费,按分辨率和是否含视频输入分档。支持 创建素材资产组合、上传素材、获取素材详情、更新素材、删除素材、查询任务、创建任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.4
summary: "「Seedance 2.0」的完整调用封装:7 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 104)May include surrounding context.

md
name: seedance-video
slug: seedance-video
displayName: 三剪客 · Seedance 2.0
description: "基于火山方舟 Seedance 2.0 的多模态视频生成应用。支持文本/图片/视频/音频任意组合输入,可输出 480p/720p/1080p 分辨率、4~15 秒时长的视频,并可选生成同步音频。按 token 计费,按分辨率和是否含视频输入分档。支持 创建素材资产组合、上传素材、获取素材详情、更新素材、删除素材、查询任务、创建任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.4
summary: "「Seedance 2.0」的完整调用封装:7 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: seedance-video
slug: seedance-video
displayName: 三剪客 · Seedance 2.0
description: "基于火山方舟 Seedance 2.0 的多模态视频生成应用。支持文本/图片/视频/音频任意组合输入,可输出 480p/720p/1080p 分辨率、4~15 秒时长的视频,并可选生成同步音频。按 token 计费,按分辨率和是否含视频输入分档。支持 创建素材资产组合、上传素材、获取素材详情、更新素材、删除素材、查询任务、创建任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.4
summary: "「Seedance 2.0」的完整调用封装:7 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
name: seedance-video
slug: seedance-video
displayName: 三剪客 · Seedance 2.0
description: "基于火山方舟 Seedance 2.0 的多模态视频生成应用。支持文本/图片/视频/音频任意组合输入,可输出 480p/720p/1080p 分辨率、4~15 秒时长的视频,并可选生成同步音频。按 token 计费,按分辨率和是否含视频输入分档。支持 创建素材资产组合、上传素材、获取素材详情、更新素材、删除素材、查询任务、创建任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.4
summary: "「Seedance 2.0」的完整调用封装:7 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
name: seedance-video
slug: seedance-video
displayName: 三剪客 · Seedance 2.0
description: "基于火山方舟 Seedance 2.0 的多模态视频生成应用。支持文本/图片/视频/音频任意组合输入,可输出 480p/720p/1080p 分辨率、4~15 秒时长的视频,并可选生成同步音频。按 token 计费,按分辨率和是否含视频输入分档。支持 创建素材资产组合、上传素材、获取素材详情、更新素材、删除素材、查询任务、创建任务。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
version: 1.0.4
summary: "「Seedance 2.0」的完整调用封装:7 个接口的官方文档、参数表与一个零依赖客户端。包内含完整操作文档与零依赖客户端(`SKILL.md` + `references/`)。需要自备 api.a7w.cn 的 API Key,注册领 Key 见 https://api.a7w.cn/ 。遇到问题可加技术微信 9872659。"
license: MIT

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill prominently includes deletion of assets but gives no warning about permanence, scope, or recovery limitations. In an agent setting, destructive operations without explicit user confirmation increase the risk of accidental data loss or irreversible deletion of user-provided media assets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation exposes a web_search tool that sends prompts or derived query content to external network services, but it does not warn users that their input may leave the local workflow boundary. In a multimodal generation skill, prompts can contain sensitive business, personal, or proprietary information, so omitting this disclosure can lead to unintended data exfiltration through search requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The callback_url field causes task status and results to be delivered to a user-specified external endpoint, yet the documentation does not warn that generated outputs and metadata will be transmitted off-platform. This creates a risk of silent data leakage, SSRF-style misuse by directing callbacks to sensitive internal endpoints, or accidental delivery of private media/results to unintended destinations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file describes a deleteAsset API that deletes assets, which is a destructive operation affecting user data. The document provides endpoint and parameter details but includes no warning, confirmation guidance, or caution that the action may permanently remove the asset.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file is presented as part of a Seedance video-generation skill, but the implementation is a generic marketplace client able to access any app/API exposed by the remote platform. This scope expansion is dangerous because an agent or user expecting only Seedance operations may unknowingly grant a credentialed tool much broader remote capability than declared.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The dump functionality enumerates all available apps and exports all schemas from the plugin market, which materially exceeds the skill's stated Seedance-focused purpose. In an agent setting, this broad discovery capability can facilitate unintended access to unrelated tools and increase the blast radius of the provided API key.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The call command accepts arbitrary app and api arguments and forwards user-supplied JSON to the remote marketplace, enabling use of any remote capability reachable by the API key. In the context of a narrowly described media-generation skill, this is a significant scope-deviation vulnerability because it can turn the skill into a general-purpose privileged API proxy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire getting-started guide is written only in Chinese, including all user-facing instructions and examples, with no indication that other languages are supported or that Chinese is required for a specific regional/compliance reason. Under the policy rule, this is a natural-language locale constraint without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill stores an API key in a local config file and also supports reading credentials from environment variables. While the docstring notes the path and permission mode, it does not clearly warn users that sensitive credentials will be persisted locally or that environment variables may expose secrets to other local processes or shell history.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.