Back to skill

Security audit

seedance2-prompter

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a Seedance video-prompt helper, but it includes explicit guidance for reworking copyrighted or brand-like prompts after platform rejection.

Review this skill carefully before installing. It does not appear to access your files, credentials, network, or system settings, but it may steer agents toward rewriting branded or character-like video prompts after platform rejection instead of stopping and creating clearly original concepts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 199)May include surrounding context.

md
- `SKILL.md` — 主技能行为定义

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This file explicitly frames its purpose as avoiding Seedance platform IP review and provides concrete tactics to preserve recognizable copyrighted characters while reducing detection. In the context of a prompt-engineering skill, that is dangerous because it operationalizes policy evasion and likely facilitates copyright infringement and moderation bypass rather than legitimate creative assistance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation rules are broad enough to trigger on many ordinary video, prompt, or storyboard requests, which can cause the skill to activate outside its intended niche. Over-broad routing increases the chance that users are steered into this skill’s stronger behavioral constraints and review-bypass guidance when they did not ask for it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states that it creates English prompts by default, which overrides user language preference unless the user explicitly opts in. This is primarily a safety and UX control issue: forced output format can degrade transparency, cause misunderstandings, and make it easier to slip in content transformations the user did not request.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This section explicitly provides an iterative strategy to evade platform IP/content review by rewriting blocked branded or character content while preserving the intended aesthetic. That is dangerous because it meaningfully assists users in bypassing trust-and-safety enforcement and enables generation of infringing or policy-violating content that would otherwise be stopped.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script’s comments and runtime output are presented in Chinese, including the title, usage context, and request echo labels. This imposes a specific language on users without opt-in or any documented reason that the skill is region-specific, which matches the locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file imposes a specific language/locale for its instructions without offering an alternative or stating that the language is optional. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The substitution examples explicitly preserve the semantic identity of well-known IP while swapping out trigger terms and iconic features just enough to avoid literal-name detection. That is dangerous because it helps users recreate recognizable protected content and circumvent moderation through paraphrasing rather than producing genuinely original prompts.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The '三级渐进规避' section gives stepwise escalation instructions for defeating IP screening when earlier attempts are rejected, culminating in progressively stronger disguise strategies. This is dangerous because it teaches iterative moderation evasion and enables users to continue pursuing prohibited copyrighted depictions after enforcement signals rejection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill reference is written as mandatory Chinese guidance and includes prescriptive prompt-writing instructions, but it does not indicate that users may choose another language or that the locale restriction is intentional and justified. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents the skill content in a specific language/locale, starting with the Chinese title at L001, and the surrounding section headings and instructions continue in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation when no alternative or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

Line L003 says users should use the following English terms in Seedance 2.0 prompts, which imposes a specific language choice in natural-language guidance. Because the file does not indicate that English is optional or user-selected, this may conflict with a language/locale policy requiring user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown guidance states that narration language follows the user's specification, but defaults to Chinese if unspecified. That imposes a language default rather than offering a neutral choice or explicit opt-in, which can conflict with organizational language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.