Back to skill

Security audit

Seedance Video Generation

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward CellCog video-generation integration, with the main caveat that prompts and reference media are sent to an external service.

Install only if you are comfortable sending your video prompts and any attached image, video, or audio references to CellCog and its model providers. Avoid uploading confidential, regulated, or copyrighted internal material unless your organization has approved that use and reviewed CellCog's data handling terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs users to send prompts and up to 50 reference files to CellCog/Seedance, an external service, but does not clearly warn that user content, media, and possibly sensitive data will leave the local environment. This can lead to inadvertent disclosure of confidential information, regulated data, or copyrighted/internal assets because users are encouraged to upload substantial reference material without any privacy or retention notice.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.