Back to skill

Security audit

Seedance 2

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward PoYo video-generation helper, with expected third-party API and API-key use but no hidden install, persistence, or unrelated data access.

Install only if you trust PoYo with the prompts, media URLs, callback URLs, and generated task data you submit. Prefer POYO_API_KEY from an environment variable or secret manager, avoid sensitive or internal-only URLs, and use callback URLs you control.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The reference explicitly encourages sending user-supplied media URLs and an optional callback URL to a third-party API, but it does not warn that this discloses those URLs and associated content to PoYo and causes PoYo to make outbound requests to those endpoints. In a skill context, users may assume uploaded or linked assets remain local, so the omission can lead to unintentional privacy leaks, disclosure of internal URLs, or unsafe callback usage.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.