Back to skill

Security audit

Madstory(Seedance Storyboard Engine)

Security checks across malware telemetry and agentic risk

Overview

This is a static creative storyboarding skill with some overbroad routing and language-default issues, but no hidden execution, credential access, persistence, or data exfiltration instructions.

Installers should treat this as a Chinese-first creative prompt/storyboard skill. Confirm the mode and output language before relying on results, especially for generic image requests or multilingual deliverables. Review any user-provided media before uploading it to external generation platforms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list contains very broad generic phrases such as '文生图', '图生图', '图像编辑', and '多语种', which are likely to match many ordinary user requests unrelated to this specific storyboard skill. That can cause unintended activation, prompt hijacking of unrelated workflows, and user confusion by routing benign requests into a highly specialized agent without clear consent.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The example file is entirely in Chinese and does not indicate any user language choice, fallback, or opt-in behavior. This can cause exclusion, misunderstanding, or unintended behavior for users expecting another language, but it does not appear to be a malicious security mechanism in this creative-storyboarding context.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The text explicitly mandates a specific output language in the final generated content: all on-screen text must be entirely in Korean and must not contain Chinese, English, or other languages. Because this is framed as a hard requirement rather than a user-selected preference, it can override user intent or system behavior and cause unauthorized output steering. In this skill context, that is a genuine policy/control issue, though less severe than code execution or data exfiltration.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The instruction mandates a specific output language for the final artifact regardless of user preference, which can violate locale and user-intent expectations. In this skill context, it is especially risky because it governs generated user-facing media text and subtitles, so it can silently produce unusable or misleading deliverables for users who did not request Korean.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The load condition is broad enough to activate this rule file for many loosely related requests, including generic image generation, editing, or knowledge-visualization scenarios. In an agent skill, overly permissive conditional loading can cause prompt/routing confusion, make the system apply the wrong model-specific rules, and increase the chance of unsafe or unintended behavior being injected into downstream generation flows.

Natural-Language Policy Violations

Medium
Confidence
85% confidence
Finding
The file is entirely written as Chinese-only operational guidance and repeatedly prescribes Chinese-formatted outputs and workflows without any indication that output language should follow user preference. In an agent setting, hard-coding a language can override user intent, reduce usability, and create prompt-control issues where the skill constrains responses more than necessary.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation rule includes automatic loading on 'input validation downgrade' without defining when that downgrade occurs or what constraints apply. In an agent skill system, vague fallback loading can cause this content to be invoked outside its intended Mode 8 context, increasing the chance of prompt-routing errors, unintended behavior, or policy bypass through ambiguous classification.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.