Back to skill

Security audit

video-generator-seedance

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims: it sends user prompts to Volcengine to generate a video and saves the returned video locally.

Install only if you are comfortable sending prompts, image URLs, and related generation metadata to Volcengine. Store config.json carefully because it contains a live API key, do not commit or share it, and choose an explicit output path if you want to control where generated MP4 files are written.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'file_read' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README explains that prompts and optional image URLs are sent to Volcengine's external API, but it does not clearly warn users that their input data leaves the local environment and may be processed, logged, or retained by a third party. In a media-generation skill, prompts and reference images can contain sensitive business, personal, or copyrighted content, so lack of disclosure increases the chance of unintended data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README tells users to store a live API key in a local config.json file but gives no guidance about keeping that file out of version control, restricting file permissions, or preferring environment variables/secret stores. This creates a realistic risk of accidental credential exposure through commits, backups, screenshots, or shared project directories, which could allow unauthorized use of the external API and billing abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill documentation states that generated videos are automatically downloaded and saved locally, but the warning is only implied in workflow/notes rather than clearly surfaced as a safety warning. In an agent setting, automatic filesystem writes can surprise users, overwrite expected locations, or persist untrusted remote content without explicit informed consent, making this a real documentation-related security issue.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

The script transmits user-supplied prompt content and optional image URLs to an external third-party API, and it authenticates with a bearer API key. In this skill context that transmission is expected, but it is still security-relevant because sensitive prompts or internal image URLs could be sent off-host without validation or clear minimization, and the code also prints request/response bodies that may expose sensitive data in logs.

Content

Scanner excerpt · scripts/generate_video.py (reported line 134)May include surrounding context.

python
print()
        
        try:
            response = requests.post(
                self.create_task_url,
                headers=self.headers,
                json=payload,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code's description and all user-visible messages are written in Chinese, and it also explicitly reconfigures stdout for UTF-8 output. For a general-purpose video generation utility, this imposes a specific language/locale on users without any opt-in or documented regional limitation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest description focuses on using the SD1.5pro API for text-to-video and image-to-video generation with asynchronous task handling. In addition to that expected API interaction, the script retrieves the returned video URL and writes the video to a local filesystem path, which is extra behavior not described in the manifest.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.