Back to skill

Security audit

seedancer

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a filmmaking prompt workflow, but it includes explicit instructions to hide age/minor signals from content filters, which needs review before installation.

Review or remove the age/filter-avoidance rules before installing. Use this skill only with clear adult-safe descriptions, do not use it to weaken safety filters, and expect any API-driven generation or asset-whitelisting workflow to upload the relevant prompts or media to the configured service.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (61)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a large, integrated AIGC directing and production system with numerous specialized modules and platform-specific workflow capabilities. The supplied code does not implement any of those core functions. It is a minimal bash script that accepts an optional argument, echoes it, and outputs a hardcoded prompt template and negative constraints. There is no evidence of script analysis, pre-production asset handling, multi-shot sequencing, routing logic, JSON formatting, external tool integration, or diagnostics. While the theme loosely relates to video prompt generation, the actual primary purpose is materially narrower and substantially different from the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description advertises a comprehensive AI film-directing and production operating system with numerous specialized subsystems and integrations. The supplied code does not implement any of those core capabilities. It only scaffolds a local folder structure and README for prompt-related workspaces. While this could be a tiny supporting utility for such a system, the code chunk itself is materially narrower in purpose and lacks the advertised behavior, so the description does not accurately represent what this code actually does.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction explicitly tells the model to avoid writing ages because content filters become stricter when they detect minors, which is a direct natural-language strategy for reducing safety enforcement. This is dangerous because it helps users preserve youth-coded content while suppressing policy-relevant signals, increasing the risk of generating disallowed or borderline sexualized or violent content involving young-looking subjects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file title and all user-facing changelog content are written only in Chinese, with no indication that another language is supported or that this is a region-specific skill. Under the policy, forcing a specific language without user opt-in can be a natural-language locale violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The example trigger phrase 'Read my script and run the full pipeline from script analysis to storyboard' is framed as a natural-language invocation without any stated constraints, command prefix, or exclusion conditions. In a markdown skill description, this can be interpreted as the skill activating on a wide range of ordinary filmmaking requests rather than a narrowly scoped command.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The phrase 'Shoot a cyberpunk rain-night street, 15s, 16:9' is a generic creative request that could appear in normal conversation and does not specify why it should invoke this particular skill. The README does not provide negative examples or clear boundaries distinguishing ordinary prompt-writing requests from Seedancer activation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 185)May include surrounding context.

JSON API Automation

bash
curl -X POST https://api.clawhub.ai/v1/skills/seedancer/execute \
  -H "Content-Type: application/json" \
  -d '{"input": "Rain night, cyberpunk street, protagonist melancholic",
        "options": {"output_mode": "json", "duration": 15, "aspect_ratio": "16:9"}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 185)May include surrounding context.

JSON API Automation

bash
curl -X POST https://api.clawhub.ai/v1/skills/seedancer/execute \
  -H "Content-Type: application/json" \
  -d '{"input": "Rain night, cyberpunk street, protagonist melancholic",
        "options": {"output_mode": "json", "duration": 15, "aspect_ratio": "16:9"}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · docs/README-cn.md (reported line 187)May include surrounding context.

JSON API Automation

bash
curl -X POST https://api.clawhub.ai/v1/skills/seedancer/execute \
  -H "Content-Type: application/json" \
  -d '{"input": "Rain night, cyberpunk street, protagonist melancholic",
        "options": {"output_mode": "json", "duration": 15, "aspect_ratio": "16:9"}}'

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description lists activation terms such as “视频生成” and “提示词”, which are generic phrases commonly used in ordinary conversations about AI tools. Because the trigger list does not narrow context or provide exclusions, the skill could be invoked unintentionally for many unrelated requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The language routing table hard-codes output behavior for Chinese, English, and Japanese only, and states that prompt and explanatory text must follow the user's input language. This imposes a language policy without offering opt-in, fallback behavior, or support for other languages, which can violate organizational expectations around language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description on L05 is entirely in Chinese and does not offer any language/locale choice or explain that the skill is intended only for a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · docs/README-cn.md (reported line 187)May include surrounding context.

JSON API 自动化

bash
curl -X POST https://api.clawhub.ai/v1/skills/seedancer/execute \
  -H "Content-Type: application/json" \
  -d '{"input": "雨夜,赛博朋克街道,女主角悲伤",
        "options": {"output_mode": "json", "duration": 15, "aspect_ratio": "16:9"}}'

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file applies to SQP-3, which covers natural-language policy violations. The title and the overwhelming majority of the instructional content are in Chinese, effectively forcing a specific language experience without any opt-in, fallback, or stated regional scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains extensive natural-language instructions exclusively in Chinese, and there is no indication that users may choose another language or that the locale restriction is necessary. Under the policy rule for language/locale constraints, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file is written fully in Chinese and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the language/locale policy rule, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown skill file presents all instructions, rules, and examples exclusively in Chinese, and there is no natural-language indication that users may choose another language or that the skill is intended only for a Chinese-language audience. That can violate a language/locale policy requiring user opt-in or documented justification for a fixed language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains natural-language instructions exclusively in Chinese, with no opt-in, alternative language, or justification for a Chinese-only requirement. Under the policy criteria, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction mandates using Chinese labels and names whenever the canonical script name is Chinese. This is a natural-language locale policy constraint presented as mandatory behavior, and the file does not offer the user a language choice or opt-in for this case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file title and all operational prompts/instructions are written exclusively in Chinese, and the protocol defines user-visible messages in Chinese without indicating that language selection is optional. This creates a natural-language locale constraint that appears mandatory rather than user-chosen or justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file explicitly instructs the model to include violent physical effects such as blood behavior, weapon weight, and injury continuity. Under the markdown-file warning criterion, the description should disclose that outputs may include graphic violence or injury-related content because it can affect user safety expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file title and all instructional content are written exclusively in Chinese, which constitutes a language-specific constraint in the skill documentation. The policy says to flag language or locale restrictions unless the skill offers user choice or clearly justifies the constraint as region-specific, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill document is written only in Chinese and does not indicate that users may choose another language or that the protocol is restricted to a Chinese-specific regulatory or operational context. Under the language/locale policy rule, a skill that effectively forces a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file presents all instructions, examples, and output requirements only in Chinese. Under the policy, forcing a specific language without user opt-in or a documented justification can be a natural-language policy violation because users who do not read that language cannot safely or correctly use the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. This markdown file presents all operational guidance, warnings, and templates exclusively in Chinese, with no indication that users can choose another language or that the locale restriction is intentional and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.