Back to skill

Security audit

Seedance1.5 视频生成与编辑

Security checks across malware telemetry and agentic risk

Overview

This video skill mostly matches its stated purpose, but its activation scope is very broad for a tool that uploads local media and can use paid API credits.

Review this before installing if you handle private product footage, customer assets, or paid API budgets. Use it only when you intend to send selected media and prompts to AI Hive or its upload storage, and prefer explicit commands with known file paths and output directories.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill documentation describes capabilities that read environment variables, access local files, write configuration and outputs, invoke shell commands, and make network requests, yet no permissions are declared. This creates a transparency and consent problem: users and platform controls may not understand that local credentials, media, and filesystem locations will be accessed and sent to a remote API.

Tp4

High
Category
MCP Tool Poisoning
Confidence
86% confidence
Finding
The skill claims to be narrowly scoped to Seedance 1.5 video workflows, but the documented behavior indicates broader AI Hive account and client functionality, including model enumeration, media upload, API key setup, and account-related access. Scope mismatch is dangerous because users may authorize a specialized video skill while it can interact with a much wider set of remote capabilities and sensitive account context.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The file embeds a full general-purpose AI Hive client with chat, image generation, model enumeration, user-info, upload, and task management capabilities, while the declared skill is narrowly scoped to Seedance 1.5 video generation/editing. In an agent-skill setting, this scope expansion is dangerous because it gives the skill access paths and data-handling behaviors the user would not reasonably expect, increasing the blast radius for misuse or accidental sensitive-data exposure.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The top-level documentation explicitly presents the file as a generic AI Hive capability wrapper rather than a Seedance 1.5-specific skill. That mismatch can mislead reviewers, users, or policy layers about what the code is actually capable of, which weakens trust boundaries and makes over-privileged behavior easier to hide.

Vague Triggers

Medium
Confidence
79% confidence
Finding
The activation text is extremely broad and designed to match many generic video, e-commerce, and competitor-tool queries, which increases the chance of unintended invocation. Overbroad triggering can cause users to enter a workflow that uploads local media and uses paid remote APIs even when they did not specifically request this skill.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The sections covering competitor names, e-commerce platforms, and broad search intents substantially widen the invocation surface without clear boundaries. In context, this is more dangerous because the skill performs remote uploads, task submission, and output downloads, so accidental matching can lead to privacy exposure or paid operations from loosely related user requests.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The description does not prominently warn that local image, video, and audio files will be automatically uploaded to a remote service before generation. This is a significant privacy and data-governance issue, especially for sensitive or proprietary creative assets, because users may believe processing is local or may not realize third-party transfer occurs.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.