Back to skill

Security audit

Seedance 2.0 video prompter

Security checks for vulnerabilities and agentic risk

Overview

This Markdown-only Seedance prompt helper is mostly coherent, but it includes explicit copyright/platform-review avoidance guidance that users should review before installing.

Use this only if you want a Chinese-focused Seedance prompt-writing helper. Before installing, review or remove the IP/copyright avoidance guidance and avoid using it to imitate protected brands, characters, or styles; use original or properly licensed references instead. Also be aware that the broad trigger terms may affect ordinary video, storyboard, or product-promo requests.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/recipes.md (reported line 9)May include surrounding context.

A) 电影级冒险(10s)

text
Mode: All-Reference

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/recipes.md (reported line 9)May include surrounding context.

A) 电影级冒险(10s)

text
Mode: All-Reference

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description includes broad trigger terms like video generation, prompt, and product showcase that can match many ordinary requests and cause the skill to activate outside its intended niche. Over-broad activation can unexpectedly steer unrelated conversations into this skill's rigid prompting workflow, degrading user intent handling and creating prompt-scope hijacking risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

Declaring the skill as Chinese-optimized without offering a language choice can force behavior that does not match user preference and may reduce transparency or usability for non-Chinese users. This is primarily a policy and UX scoping issue rather than a direct security exploit, but it can contribute to inappropriate skill activation and user confusion.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The read_when list uses short, generic phrases such as 分镜设计, 镜头语言, 电商视频, and 产品展示视频 without qualifiers, which are common across many benign creative tasks unrelated to this skill. This makes unintended invocation likely and can cause the agent to apply specialized constraints and outputs when the user did not request Seedance-specific assistance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instruction that users describe needs in Chinese imposes a language constraint without consent, which can override user intent and create mismatched outputs. In context this is not highly dangerous, but it is still an undesirable hard-coded behavior that may cause the agent to mishandle multilingual or English-language requests.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The IP/版权规避 section gives stepwise instructions for progressively evading platform moderation while preserving recognizable copyrighted aesthetics, including what to do after rejection. That is dangerous because it operationalizes policy evasion and enables users to generate infringing or disallowed derivative content despite platform safeguards.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The phrase 'IP规避' explicitly signals functionality aimed at avoiding intellectual-property restrictions, which can enable copyright evasion, trademark mimicry, or deliberate bypass of safety and policy controls around protected content. In the context of an AI video prompt skill, this makes the skill more dangerous because it operationalizes generation workflows that may help users produce infringing or policy-violating outputs at scale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description states the skill is a '中文优化版' (Chinese-optimized version), which imposes a language/locale constraint in the natural-language metadata. There is no indication that users can choose another language or opt into this locale behavior, which matches the language-policy concern for this rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Line L003 says to use the following English terms in Seedance 2.0 prompts, which imposes a specific language requirement. The file does not indicate that other languages are acceptable, nor does it provide a user opt-in or a documented reason for the constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. Line L003 presents the template library as directly usable with Chinese-only explanatory annotations, with no indication of alternative language support or user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.