Back to skill

Security audit

Madstory(Seedance Storyboard Engine)

Security checks for vulnerabilities and agentic risk

Overview

MadStory is mostly a coherent storyboard prompt skill, but its optional HTML preview template has a real browser injection risk if it renders untrusted storyboard data.

Review before installing if you plan to use the HTML storyboard preview with content from other people or untrusted sources. The prompt workflow itself is purpose-aligned, but generated previews should sanitize storyboard fields or avoid hosting them in a privileged browser origin. Use uploaded voice, image, and video references only with appropriate rights and consent.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
assets/storyboard_template.html:394
Finding

DOM-Based HTML Injection in Storyboard Timeline Rendering

Content
View full analysis
{ const pct = ((shot.duration || 5) / total * 100).toFixed(1); const color = colors[i % colors.length]; return `
${i+1}
`; }).join(''); ``` ### Technical Analysis The timeline renderer obtains storyboard entries from `window.__SHOT_DATA__` and constructs HTML by interpolating their properties into a template string. The resulting string is assigned to `bar.innerHTML`. In particular, `shot.name` and the displayed `shot.duration` are inserted into the `title` attribute without contextual escaping or sanitization. An attacker who can influence storyboard data can terminate the attribute and inject new HTML attributes or elements. Browser parsing of the resulting `innerHTML` can therefore introduce event handlers or other script-capable markup. The percentage calculation converts the duration to a number before placing it in the `style` width, but the original duration is also inserted directly into the `title` attribute. The conversion used for width calculation does not sanitize the separately interpolated value. ### Attack Path 1. An attacker supplies or modifies storyboard data consumed as `window.__SHOT_DATA__`. 2. The attacker places an attribute-breaking payload in `shot.name`, for example a value containing a quotation mark followed by an event-handler attribute. 3. `renderTimeline()` interpolates that value into the `title` attribute. 4. The generated string is assigned to `bar.innerHTML`. 5. The browser parses the injected markup as active DOM content. 6. The injected event handler executes when its triggering condition occurs, such as us ...[truncated 883 chars]
Remediation
View remediation
{ const value = Number(shot.duration); return Number.isFinite(value) && value > 0 ? value : 5; }); const total = durations.reduce((sum, value) => sum + value, 0); bar.replaceChildren(); shots.forEach((shot, i) => { const duration = durations[i]; const pct = (duration / total * 100).toFixed(1); const segment = document.createElement('div'); segment.className = 'timeline-segment'; segment.style.width = `${pct}%`; segment.style.background = colors[i % colors.length]; const safeName = typeof shot.name === 'string' ? shot.name.slice(0, 200) : `Shot ${i + 1}`; segment.title = `${safeName}: ${duration}s`; segment.textContent = String(i + 1); bar.appendChild(segment); }); } ``` ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (23)

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Line L038 explicitly describes a multilingual mode as 'forced language output'. This is a direct natural-language policy concern because it instructs the skill to enforce a language rather than letting the user choose or making the constraint contextually explicit.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

All user-facing instructions and examples in the README are presented in Chinese, and there is no indication that users may choose another language or that the Chinese-only presentation is intentional for a region-specific audience. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list contains many broad or commonly used phrases, which increases the chance of unintended skill activation in unrelated conversations. In an agent environment, overbroad activation can cause the skill to intercept user requests unexpectedly, leading to prompt takeover, confusion, and possible leakage of conversation context into an unnecessary workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill declares a very large trigger surface across many adjacent domains while providing only a single broad exclusion statement, which is insufficient to prevent accidental invocation. In practice, this can make the skill overmatch unrelated creative, image-editing, or script-writing requests and steer the agent into loading extensive workflow instructions that are not relevant to the user’s actual task.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger list is extremely broad and includes generic terms such as image/video generation and short-form content concepts, which can cause the skill to activate outside its intended storyboard-design context. Over-broad activation increases the chance of prompt hijacking at the routing layer, accidental takeover of unrelated user requests, and inappropriate application of the skill’s strong procedural instructions to benign conversations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This JSON contains user-facing natural-language values in Chinese, such as mode labels and later script-format markers, but provides no indication that the user can choose a language or locale. That can violate a language/locale policy when the skill effectively assumes Chinese output or interaction conventions by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The configured script format mandates Chinese markers like "第X集", "场景:", and "人物:" as part of the natural-language interface. Because no alternative or opt-in mechanism is provided, the skill appears to enforce a specific language convention.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document declares lang="zh-CN", which hard-codes a specific language/locale for the skill output. Under the policy, locale restrictions should either be optional for the user or clearly justified as region-specific; this file provides neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill example, including headings, user input, and checklist, is presented only in Chinese and implicitly assumes Chinese-language interaction. Under the policy, locale or language constraints should either offer user opt-in or be clearly documented as justified; neither is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill includes a hard requirement that all text in the final output must be in a specified language and explicitly forbids other languages, without indicating user opt-in or confirmation. This can override user preference or system-level language behavior, causing unwanted prompt steering and reducing user control over output language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the model to force all output text in a specified language (e.g. 'all text must be Korean, prohibit Chinese/English/other languages') without requiring user opt-in or validating the user's preferences. This can override user intent, reduce transparency, and cause misleading or inaccessible outputs, especially in multilingual or compliance-sensitive contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Line L112 states that multilingual versions must use native-language dialogue plus a forced language output declaration. This imposes a language/locale requirement in natural language without indicating user choice or opt-in, which conflicts with the policy against forcing a specific language unless documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The title and the entire guidance are written as a normative specification in Chinese, and no language-selection or opt-in mechanism is described. Under the policy rule, forcing a specific language without user choice can be a locale-policy violation unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The rule explicitly instructs the model to force all generated text into a specific language and forbid other languages, without requiring user opt-in or contextual checks. In an agent skill, this can override user intent, degrade transparency, and cause unsafe or misleading output if safety warnings, UI text, or compliance-required content are translated or suppressed unexpectedly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file defines automatic intent/style detection and routing using specific Chinese keywords such as '国风/水墨/古风' and '种草/测评/开箱/口播', plus script/material markers like '第X集', '场景', and '上传/@图片/@视频/参考图'. This imposes a locale/language-specific interaction policy for activation and routing without documenting user choice or an alternative for other languages.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The load condition is broad enough to activate this ruleset for loosely related scenarios such as general image generation, editing, reference-image, or knowledge-visualization tasks. In an agent system, over-broad triggers can cause unintended skill invocation, leading to prompt/context injection, wrong tool routing, or user requests being processed under assumptions they did not intend.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The guidance encourages direct use of specific languages in multilingual rendering examples without requiring the user's language preference or explicit consent. In a user-facing agent, this can cause unwanted language switching, incorrect localized output, or generation of text the user cannot verify, which is a policy and UX risk even if not a classic code-execution issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file title and usage description are entirely in Chinese, and there is no indication that users may choose another language or that the skill is limited to a Chinese-only regional/compliance context. Per the policy, natural-language instructions that effectively impose a language without opt-in should be flagged.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill is described as a film-grade storyboard and AI video/image prompt design engine, but the README also embeds a promotional invitation to join a group chat via an external image/resource. Community promotion is not an obvious requirement for storyboard generation and falls outside the stated operational purpose of the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The style-detection configuration relies on specific Chinese keywords such as "电影感", "二次元", and "国风" mixed with some English terms, but the file does not explain how language selection works or whether non-Chinese users are supported. This creates an implicit locale assumption in natural-language behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file contains user-facing natural-language content primarily in Chinese, but the core prompt payloads and advice fields are written in English. Because no user opt-in or explanation is provided for the forced language mix, it may violate language/locale policy expectations under the natural-language policy rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document is written primarily in Chinese and presents the skill/example in that locale without any indication that users may choose another language. Under the stated policy criteria, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown reference file presents all primary instructional content in Chinese without offering a language/locale option or documenting that the Chinese-only scope is intentional, which can amount to forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.