Back to skill

Security audit

muapi-seedance-2

Security checks across malware telemetry and agentic risk

Overview

This is a coherent media-generation skill, with ordinary privacy considerations around sending prompts, images, and image URLs to an external service.

Install only if you are comfortable using the external generation provider for your prompts and media. Use a limited API key, avoid private or internal image URLs, and review shell commands before running them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill embeds executable shell command examples and operational workflows but declares no permissions, creating a mismatch between advertised capabilities and the manifest. That can mislead users or enforcement systems about what the skill may cause the agent to do, increasing the chance of unintended command execution or weakened policy controls around shell use.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly supports remote image URL ingestion for i2v workflows without warning that the agent or backing service may fetch third-party URLs and transmit retrieved content onward. This creates SSRF/privacy and data-handling risk: internal URLs, signed URLs, or sensitive user-provided links could be fetched and exposed to external infrastructure without the user's informed consent.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.