Back to skill

Security audit

Seedance2-Storyboard-Generator

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Seedance storyboard skill, but it includes explicit guidance to avoid copyright-related refusals, so it should be reviewed before use.

Before installing, review the Chinese-language templates and Seedance-specific output conventions. Use the skill only with original, licensed, or clearly permitted source material, and ignore or remove the instruction that suggests avoiding copyright refusals by renaming characters.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file presents required production parameters using Chinese labels and examples, such as 写实/动画/水墨 and 16:9横屏 / 9:16竖屏, with no indication that the user can choose another language. This creates a locale/language constraint in the skill's instructions without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill mandates Chinese field labels and filenames such as 图片1, 剧本.md, 素材清单.md, and 分镜.md, which effectively forces a specific language/locale in outputs. The policy exception does not apply because the file does not clearly justify the locale restriction or offer user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file defines the role, workflow, templates, and output requirements entirely in Chinese, and it instructs the assistant to interact with users in that language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless a justified locale restriction is documented.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction to use generic labels like 'Figure 1' and 'Figure 2' specifically to avoid copyright-related refusals is an evasion technique aimed at bypassing downstream safety or policy controls. Even though it does not directly execute code, it encourages users to conceal prohibited intent and increases the chance of generating infringing or disallowed content through another model.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is entirely written in Chinese and provides no language selection, fallback, or explicit locale constraint. This can exclude or confuse users and downstream agents that expect multilingual or default-language compatibility, leading to misuse, misunderstanding of instructions, or failure to safely apply the tool in broader contexts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.