Back to skill

Security audit

HiAPI Seedance 2.0 Video

Security checks for vulnerabilities and agentic risk

Overview

This video-generation skill is mostly coherent, but its installer and update flow give mutable remote sources too much influence over persistent agent files and user-run commands.

Review this before installing in a sensitive agent environment. Prefer OpenClaw's controlled install path or a pinned commit, avoid running unpinned npx github commands, do not accept update commands blindly from runtime output, keep HIAPI_BASE_URL unset unless you fully trust the endpoint, and use a constrained output directory with available disk space.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
scripts/lib/seedance-2-video.mjs:565
Finding

Remote Manifest Can Supply a Mandatory Arbitrary Update Command

Content
View full analysis
controller.abort(), timeoutMs) : null; try { response = await fetchImpl(manifestUrl, { headers: { Accept: "application/json" }, signal: controller?.signal, }); } catch { return { status: "skipped" }; } finally { if (timer) clearTimeout(timer); } if (!response?.ok) return { status: "skipped" }; let manifest; try { manifest = await response.json(); } catch { return { status: "skipped" }; } const skill = Array.isArray(manifest.skills) ? manifest.skills.find((entry) => entry?.id === skillId) : null; const policy = skill?.updatePolicy; if (!policy) return { status: "current" }; const minimumVersion = policy.minimumVersion || skill.version || currentVersion; const latestVersion = policy.latestVersion || skill.version || minimumVersion; const updateCommand = policy.updateCommand || "npx -y github:HiAPIAI/hiapi-seedance-2-0-video-skill -y"; if (compareVersions(currentVersion, minimumVersion) < 0) { return { status: "required", message: [ policy.requiredNotice || "This HiAPI skill version is no longer compatible with the current HiAPI API.", ...[truncated 3197 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/install.mjs:101
Finding

Shell Command Injection Through Installer Target Path

Content
View full analysis
a.startsWith(prefix)); return hit ? hit.slice(prefix.length).replace(/^~(?=$|\/)/, homedir()) : null; } const explicitTarget = flagValue('target') ?? flagValue('skills-dir') ?? null; ``` ```javascript async function resolveTargets() { if (explicitTarget) { return [{ label: 'explicit', dir: explicitTarget }]; } if (env.AGENT_SKILLS_DIR) { return [{ label: '$AGENT_SKILLS_DIR', dir: env.AGENT_SKILLS_DIR }]; } ``` ```javascript function installTo(target) { mkdirSync(target.dir, { recursive: true }); const destination = join(target.dir, SKILL_FOLDER); if (existsSync(destination)) { console.log(`[${DISPLAY_NAME}] ${destination} exists — replacing.`); rmSync(destination, { recursive: true, force: true }); } console.log(`[${DISPLAY_NAME}] Cloning into ${destination} …`); execSync(`git clone --depth 1 ${REPO_URL} "${destination}"`, { stdio: 'inherit' }); } ``` ### Technical Analysis The installer accepts a destination from `--target`, `--skills-dir`, or `AGENT_SKILLS_DIR` and interpolates the resulting path into a shell command passed to `execSync()`. Placing the destination inside double quotes does not make the shell command safe. POSIX shells still process command substitution such as `$(...)` and backticks within double-quoted strings. A malicious path containing an embedded quote can also terminate the intended argument and append additional shell syntax. The path is not validated or escaped for shell interpretation. The vulnerable operation is unnecessary because Node.js supports argument-array process execution that does not invoke a shell. ### Attack Path 1. An attacker persuades a victim or automation system to run the installe ...[truncated 1201 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/install.mjs:8
Finding

Installer Retrieves and Executes an Unpinned Upstream Repository State

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/lib/seedance-2-video.mjs:33
Finding

Bearer API Key Can Be Sent to an Arbitrary or Plaintext Base URL

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/lib/seedance-2-video.mjs:414
Finding

Unbounded Remote Video Download Can Exhaust Memory and Disk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (39)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 123)May include surrounding context.

md
node scripts/check-config.mjs

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The README instructs users to execute npx -y github:HiAPIAI/hiapi-seedance-2-0-video-skill without pinning a commit, tag, or package version. That causes installation code to be fetched from a mutable remote source at execution time, creating a supply-chain risk where a compromised repository, force-pushed tag, or malicious update could lead to arbitrary code execution on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This command executes installer code directly from GitHub using npx and does not pin the repository to an immutable version. If the upstream repository is modified or compromised, anyone following the README could run attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The --codex install example still relies on npx -y github:... without an immutable version. The extra flag changes target location but does not reduce the core supply-chain risk of executing mutable remote code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This Claude-targeted install command executes remote GitHub code without version pinning. A user may believe the command is routine agent setup, but it still grants arbitrary code execution to whatever content is served from that repository reference at install time.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The custom-target install command uses the same unpinned npx github: pattern and is therefore vulnerable to remote code changes. Because it is presented as a normal installation path, it increases the chance that users will execute it without reviewing the fetched code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The agent auto-install prompt explicitly tells agents or users to run an unpinned GitHub package via npx. This is especially risky in agent contexts because automated workflows may execute the command with little human scrutiny, amplifying supply-chain compromise impact.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The upgrade guidance tells users to run the same unpinned npx github: command for updates. While functionally convenient, it repeatedly exposes users to mutable remote code execution whenever they upgrade.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The compatibility section repeats the unpinned GitHub npx install pattern for Codex. Repetition across the README normalizes unsafe installation behavior and increases the number of contexts where users may execute mutable remote code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This Claude Code compatibility example uses an unpinned GitHub source with npx, exposing users to arbitrary code execution if the repository changes. The agent-specific framing may make the risk less obvious to readers who treat it as standard setup documentation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The OpenCode installation example again executes unpinned remote code from GitHub. Since this is a copy-paste-ready command, a compromised upstream could achieve immediate code execution in the user's environment and potentially access agent credentials or local files.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The generic Cursor/other install path still relies on npx -y github: without any version pinning. In a security-sensitive agent skill ecosystem, this context makes the issue more dangerous because installation often occurs in developer environments containing API keys, source code, and agent configuration.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The README instructs users to install and execute code directly from a GitHub repository via npx -y github:... without pinning to a specific commit, tag, or release. That means future repository changes can silently alter the code executed on user machines, creating a supply-chain risk that could lead to arbitrary code execution during installation.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.zh-CN.md (reported line 48)May include surrounding context.

安装脚本会自动检测 Codex(~/.codex/skills)和 Claude Code(~/.claude/skills)。如果两个都存在,-y 会同时装到两个目录。指定 Agent 或自定义目录:

bash
npx -y github:HiAPIAI/hiapi-seedance-2-0-video-skill --codex          # 只装到 ~/.codex/skills
npx -y github:HiAPIAI/hiapi-seedance-2-0-video-skill --claude         # 只装到 ~/.claude/skills
npx -y github:HiAPIAI/hiapi-seedance-2-0-video-skill --target=/path   # 自定义目录
AGENT_SKILLS_DIR=/path npx -y github:HiAPIAI/hiapi-seedance-2-0-video-skill -y

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This install command executes an unpinned GitHub-hosted package through npx, so the exact code run depends on the current repository state at install time. If the repository, maintainer account, or dependency chain is compromised, users may execute attacker-controlled code locally.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The README recommends an installation path that fetches executable content from GitHub without version pinning. Because this is an agent skill installer that writes into local skill directories, compromise of the fetched code could persist malicious behavior into future agent sessions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Using npx -y github:... without a fixed version allows silent code drift and makes the trust boundary depend on the latest repository contents. In this context, the installer can modify local agent configuration/skill paths, so exploitation could result in code execution and persistence.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This command again relies on executing mutable GitHub content through npx, exposing users to supply-chain compromise and unreviewed code execution. Because the command supports custom target paths, a malicious update could write unexpected files to attacker-chosen or sensitive locations accessible by the user.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The 'copy for your Agent' section tells the agent/user to run an unpinned GitHub npx install command, which can lead to arbitrary code execution from changing repository contents. Embedding this in automation guidance increases risk because users or agents may execute it with little scrutiny.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The compatibility section repeats an unpinned npx github: install pattern, preserving the same supply-chain and arbitrary-code-execution risk. Repetition across the README increases the chance that users will choose an unsafe installation path.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This command instructs Codex users to install the skill by executing unpinned GitHub content. In an agent ecosystem, such installation can grant persistent influence over future prompts/actions, amplifying the effect of a repository compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The Claude Code installation example executes mutable GitHub-hosted code with npx, creating a direct software supply-chain risk. Since the installer writes into agent skill directories, exploitation could establish persistence or tamper with agent behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This OpenCode example still uses an unpinned npx github: reference, so users are asked to run whatever code is currently in the repository. That creates a realistic path for attacker-controlled updates to execute and install persistent agent-side content.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The custom-target installation command again executes unpinned remote code and may write into arbitrary directories. If the installer is ever compromised, this pattern could be abused to place malicious files in locations the user did not fully assess.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill clearly instructs the agent to make outbound API calls to HiAPI, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates a governance gap where a reviewer or execution environment may not have a clear, machine-readable restriction on network use, increasing the risk of unintended external requests or over-broad execution privileges.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/install.mjs:94

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/lib/seedance-2-video.mjs:33

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/lib/seedance-2-video.mjs:34