Back to skill

Security audit

seedancer

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Seedance video-prompt workflow helper with no hidden execution, credential access, or background behavior found.

Install if you want a Chinese-first Seedance video prompt workflow. Review generated prompts before submitting them to any video platform, and independently verify current Seedance platform limits, pricing, and capabilities when they matter.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill declares very broad trigger phrases such as “视频生成”, “提示词”, and “Seedancer”, which can overlap with common user requests and cause the skill to activate outside its intended scope. Over-broad activation increases the chance of unintended routing, user confusion, and the application of this skill’s rigid workflow when the user did not ask for it.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The description is predominantly Chinese and presents a Chinese-centered workflow and terminology without clearly stating multilingual behavior or user-language fallback at activation time. This can cause the skill to steer users into a language-specific interaction model they did not choose, degrading usability and potentially causing misunderstanding of important review or safety steps.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.