Back to skill

Security audit

Idea to Seedance Video

Security checks for vulnerabilities and agentic risk

Overview

This skill is a content-writing guide for turning creative ideas into Seedance video scripts and prompts, with no evidence of hidden code or unsafe system access.

This skill is reasonable to install for Seedance prompt and storyboard help. Users should still review generated prompts before uploading assets to any video platform, especially media with identifiable people, brand materials, or copyrighted references.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
- Generated video duration: choose 4-15s.
- Current entries: use `首尾帧` for first-frame/last-frame style work; use `全能参考` for multimodal references. Do not recommend `智能多帧` or `主体参考` for Seedance 2.0 when following this guide.
- Use `@素材名` in prompts to assign roles, such as `@图片1 作为首帧`, `@视频1 参考运镜和动作节奏`, `@音频1 用于配乐`.
- Do not ask the user to upload realistic identifiable human-face images or videos; the guide says these are currently blocked by compliance checks.

## Image Prompt Guidance

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The notes prescribe prompt syntax and examples primarily in Chinese, including exact phrases such as 首尾帧, 全能参考, and full Chinese prompt templates, but do not state that Chinese is optional or that the skill is region-specific. This can amount to a language/locale policy issue because it implicitly forces a specific language for use without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.