Back to skill

Security audit

Seedance 2.0 Pro — Pro Pack on RunComfy

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward RunComfy video-generation guide, but prompts and referenced media are sent to RunComfy for processing.

Use this only with media and prompts you are comfortable sending to RunComfy and its model infrastructure. Avoid private, regulated, biometric, confidential, or third-party media unless you have permission and understand the provider's handling practices.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The examples explicitly encourage sending image, video, and audio references to RunComfy-hosted infrastructure, but the nearby guidance does not prominently warn users that sensitive biometric, personal, or confidential media will be transmitted to a third party. Because this skill is specifically built for multimodal media generation, users may upload faces, voices, or private footage without understanding the privacy implications, retention risks, or downstream provider access.

Static analysis

No suspicious patterns detected.