idea-to-seedance-video

Security checks across malware telemetry and agentic risk

Overview

This Seedance video skill is purpose-aligned and disclosed, though users should be aware it may upload media to a third-party video API and can incur generation costs.

Install only if you intend to use Seedance/Volcengine video generation. Set ARK_API_KEY carefully, avoid using private or sensitive media unless you accept sending it to the provider, and confirm before running paid API generation or callback commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill advertises an extremely broad set of creative-writing and video-planning uses, which can cause the agent to invoke it for generic brainstorming, scripting, polishing, or prompt-writing requests outside a narrowly defined domain. Overbroad activation increases the chance of misrouting user requests, unintended prompt capture, and interference with other more appropriate skills, especially because the description overlaps with common creative tasks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal