Back to skill

Security audit

Seedance 2.5 Image to Video — 720p Still-to-Video with Native Audio

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed RunComfy image-to-video helper that sends a user-provided prompt and public image URL to an external paid model API.

Before installing, understand that using this skill can incur RunComfy charges and will send your prompt and a public image URL to RunComfy. Avoid private or token-bearing image URLs, and confirm the intended model and duration before running generations from broad requests like "animate this image."

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger list includes broad natural-language phrases such as "animate this image" and "still to video," which are generic enough to match ordinary user requests that may not specifically intend to invoke this skill. This can cause unintended activation, leading to accidental third-party API use, cost-incurring runs, or routing the user into a tool they did not explicitly choose.

Static analysis

No suspicious patterns detected.