Back to skill

Security audit

Poyo Seedance 2

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward PoYo video-generation helper that sends user-provided prompts and media URLs to the disclosed PoYo API.

Install only if you intend to use PoYo's external API. Avoid submitting secrets, internal-only callback URLs, private media, or confidential prompts unless that sharing is approved, and prefer using the POYO_API_KEY environment variable rather than passing the key on the command line.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The examples instruct users to send prompts, callback URLs, and externally hosted media URLs to a third-party API, but the reference does not clearly warn that this transmits potentially sensitive user content and metadata outside the local system. In a skill context, this omission can lead operators to unknowingly expose confidential prompts, internal URLs, or private media to an external provider.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.