Back to skill

Security audit

Seedance 2.0 Shot Design

Security checks for vulnerabilities and agentic risk

Overview

The skill is mainly a video-prompt helper, but its documentation includes an unsafe remote CLI installer and some platform-bypass wording that users should review before installing.

Install only if you want a Seedance-focused prompt-writing skill and are comfortable with broad auto-activation for video-prompt requests. Do not run the documented CLI installer as written; use a verified, versioned installer or official package channel instead. Treat any guidance about avoiding content blocks or moderation as a compliance risk and use only original, licensed, or clearly permitted content.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/seedance-specs.md:105
Finding

Unverified Remote Installer Is Executed Directly by a Shell

Content
View full analysis

Vulnerability Details

File Location: references/seedance-specs.md, lines 105-111
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

markdown
## 即梦 CLI 联动指南(v1.8.4 新增)

> 当 Shot Design 部署在支持 CLI 调用的 Agent 环境中(如 OpenClaw + Dreamina CLI),提示词可以直接通过 CLI 提交生成。本节提供命令映射速查。

### CLI 安装

```bash
curl -fsSL https://jimeng.jianying.com/cli | bash
dreamina login   # 首次登录
text

### Technical Analysis

The installation instruction downloads a mutable response from `https://jimeng.jianying.com/cli` and passes it directly to `bash`. There is no version pinning, checksum validation, publisher-signature verification, local inspection step, or documented description of the installer’s expected behavior.

HTTPS protects transport integrity when the endpoint and certificate infrastructure remain trustworthy, but it does not establish that the remote script is safe or immutable. If the endpoint, hosting account, deployment pipeline, DNS/TLS infrastructure, or upstream content is compromised, arbitrary replacement commands would be executed immediately.

The Skill’s principal declared function is to produce structured video prompts. Installing a remote CLI is optional and is not necessary for that core function. Moreover, `SKILL.md` declares `execution: none`, but its semantic routing directs users interested in CLI or local generation to this reference. The command therefore introduces a local code-execution path beyond the minimum privileges required for prompt design.

No evidence in the audited package establishes the contents or trustworthiness of the remote installer. This finding concerns the unsafe installation mechanism; it does not assert that the current remote response is malicious.

### Attack Path

1. A user requests CLI integration, command-line operation, or local video generation.
2. The routing rule in `SKILL.md` directs the Agent or user to the CLI integration section of `references/seedance-s
...[truncated 1395 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the direct curl | bash pipeline.

  2. Distribute the CLI through a documented, versioned official release channel or a trusted package repository.

  3. Pin installation instructions to an explicit version rather than a mutable endpoint.

  4. Download the artifact as a separate step so users can inspect it before execution.

  5. Publish and require verification of a cryptographic publisher signature. If signatures are unavailable, provide a SHA-256 checksum over a versioned immutable artifact.

  6. Use an installation flow similar to:

    bash
    curl --fail --show-error --location \
      --output dreamina-installer-vX.Y.Z.sh \
      https://example.invalid/releases/vX.Y.Z/dreamina-installer.sh
    
    echo "<PINNED_SHA256>  dreamina-installer-vX.Y.Z.sh" | sha256sum --check
    less dreamina-installer-vX.Y.Z.sh
    bash dreamina-installer-vX.Y.Z.sh
    
  7. Replace the placeholder URL and checksum above only with an authenticated, immutable official release and its independently published checksum or signature.

  8. Document files, directories, credentials, network endpoints, and permissions used by the installer.

  9. Explicitly prohibit Agents from automatically installing or executing the CLI. Require informed user confirmation before any download or execution.

  10. Run the CLI with ordinary user privileges and never recommend sudo unless a narrowly scoped, documented operation genuinely requires it.

  11. Keep prompt generation independent of CLI installation so the Skill retains its instruction-only, least-privilege operation.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (51)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes automatic activation from very broad user requests like 'write me a video prompt,' which risks unintended invocation outside narrow Seedance-specific contexts. Overbroad triggers can cause instruction hijacking of unrelated conversations, unexpected prompt shaping, and reduced user control over when the skill's embedded policy and output format take effect.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The changelog documents expansion of trigger words to everyday expressions such as 'make a video' and 'create clip,' confirming deliberate broadening of activation scope. In agent environments, this can cause the skill to intercept unrelated requests, override user expectations, and increase the chance that hidden instructions or formatting constraints are applied without informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The changelog explicitly states the skill was expanded to auto-activate on natural, everyday expressions, which increases the chance of unintended invocation and prompt interception outside the user's intended scope. In an agent ecosystem, broad trigger coverage can cause the skill to override or steer unrelated conversations, creating confused-deputy behavior and reducing user control.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The document instructs users to install a CLI by piping a remote script directly into bash, which executes unverified code immediately. If the remote server, network path, or hosting account is compromised, users could run attacker-controlled commands on their machine with the privileges of the current user.

Content

Scanner excerpt · references/seedance-specs.md (reported line 110)May include surrounding context.

CLI 安装

bash
curl -fsSL https://jimeng.jianying.com/cli | bash
dreamina login   # 首次登录

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The explicit use of '| bash' creates a command-chaining pattern that removes any opportunity for review of the fetched content before execution. In an agent or CLI-enabled environment, this is especially risky because users may copy and run it verbatim, leading to arbitrary code execution if the fetched script is malicious or tampered with.

Content

Scanner excerpt · references/seedance-specs.md (reported line 110)May include surrounding context.

CLI 安装

bash
curl -fsSL https://jimeng.jianying.com/cli | bash
dreamina login   # 首次登录

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Automatically forcing Chinese or English output based on inferred user identity or language context reduces user agency and can lead to unintended disclosure, misclassification, or unsafe assumptions about preferences. In a multi-agent environment, language forcing can also alter downstream behavior, validation, or moderation outcomes in ways the user did not request.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

Lines L234-L235 explicitly state that scripts are 'NO ejecutada por el agente' and that the agent uses only a native 7-rule checklist. However, the same README repeatedly presents the validation script as part of the skill's operational validation flow and project structure, creating an intent/documentation contradiction about whether scripted validation is part of actual agent behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Repeating the automatic bilingual output policy in the version history reinforces that this is a stable behavior rather than an incidental phrasing issue. While not directly malicious, forced language routing without opt-in can create consent, usability, and policy-compliance problems, especially when integrated into broader agent workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

La description annonce « Utilisateurs chinois → chinois / autres → anglais, détection automatique », ce qui impose une langue de sortie selon une inférence automatique plutôt que selon une préférence explicite de l’utilisateur. Cela peut contrevenir à une politique de choix de langue/locale lorsqu’aucun opt-in ou mécanisme de sélection n’est proposé.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Le README indique « Dites simplement à Claude » puis donne comme exemple « Écris-moi un prompt vidéo… », en précisant que le skill « s'active automatiquement ». Cette formulation décrit une invocation par une phrase très naturelle et large, sans bornes ni exemples négatifs, ce qui augmente le risque de collisions avec des requêtes ordinaires sur la vidéo ou l’écriture de prompts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L’historique de version confirme la règle « Chinois→chinois, autres→anglais, détection auto », ce qui formalise une contrainte linguistique automatique sans mention d’un choix utilisateur. Le comportement est donc structurellement imposé plutôt qu’optionnel.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README says output language is automatically chosen based on detected user language instead of user selection. Forced language-routing can override user intent, create ambiguity in multilingual contexts, and increase the chance that safety-relevant instructions or outputs are transformed in ways the user did not explicitly request.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The phrase describing a 'copyright-safe IP avoidance' strategy to prevent platform content blocking is direct moderation- and restriction-evasion guidance. In this skill context, the feature is specifically positioned as a way to get around platform enforcement, which materially increases misuse risk for infringing or disallowed content generation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README states that a generic request like asking Claude to write a video prompt will cause the skill to auto-start, which creates an overly broad trigger surface. In an agent environment, vague activation rules can cause the skill to engage outside the user's informed intent, leading to prompt interception, unintended behavior shaping, or policy bypass through accidental routing.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The changelog describes moderation-avoidance tactics for realistic human faces by recommending blur or NPR-style conversion as a way to bypass platform review. That is explicit guidance for defeating safety controls on sensitive media generation, which is particularly dangerous because it can facilitate prohibited identity, likeness, or deceptive-content use cases.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The changelog explicitly expands automatic activation to everyday expressions, confirming that the trigger scope is intentionally broad rather than incidental documentation wording. This increases the chance of unintended invocation across unrelated conversations and makes skill behavior harder for users and host agents to reason about safely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The changelog reiterates that bilingual output is driven by automatic language detection, showing this is a designed behavior rather than a one-off description. In agent systems, automatic output transformation without clear consent can reduce predictability and interfere with user-specified constraints or downstream review processes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This is a natural-language locale policy issue because the README specifies automatic language selection based on user identity or detected language rather than explicit user opt-in. The policy exception does not apply here because no alternative language choice is offered at the point of description.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README advertises a '3-stage progressive IP avoidance strategy' to prevent platform content blocking, which is effectively guidance for evading copyright or content-review safeguards. In an agent skill, this normalizes bypass behavior and can facilitate generation of infringing or policy-violating content at scale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README presents automatic language detection as a built-in behavior and elsewhere documents the rule 중국어 사용자→중국어, 비중국어→영어, which constrains locale without user opt-in. This matches the language/locale policy violation category for all file types.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

Lines L234-L235 say scripts are developer-only and that the agent does not execute them, framing the skill as non-executing from the agent's perspective. But the README also instructs users/agents to clone a remote repository and describes OpenClaw automatically fetching and learning the skill from a GitHub URL (L57, L69-L72), which contradicts the broader 'Agent는 실행하지 않음' safety framing by involving agent-side acquisition/execution-adjacent behavior.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The changelog describes a strategy to bypass moderation on realistic human faces by reframing outputs as blurred or non-photorealistic. This is dangerous because it teaches users how to work around safety controls rather than comply with them, increasing the chance of prohibited or deceptive person-related media generation.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Advertising a way to 'bypass' a one-take platform limitation by reframing the generation mode encourages circumvention of product guardrails and intended capability boundaries. Even if framed as a creative workaround, documenting bypass techniques in a skill makes it easier to systematically evade platform constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states 'Chinese users → Chinese prompts, non-Chinese users → English prompts, auto-detected,' which imposes a language decision automatically rather than asking the user. This is a natural-language locale policy concern because it forces a language/locale behavior without explicit choice or opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README says 'Just tell Claude' followed by a generic request and states 'The Skill auto-activates,' but it does not define precise activation boundaries or exclusion conditions. This makes invocation appear to depend on common natural phrasing rather than a narrowly scoped trigger set, increasing the risk of unintended activation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.