Back to skill

Security audit

Seedance 2.5 文生视频

Security checks across malware telemetry and agentic risk

Overview

Review is recommended because the skill performs a disclosed AI video workflow, but its activation scope is much broader than that workflow and could route unrelated video-tool searches into a credential-backed, cost-bearing API flow.

Install only if you want an AI Hive Seedance 2.5 workflow and are comfortable storing an AI Hive API key locally, sending prompts and approved media to AI Hive, and potentially incurring generation costs. Treat this as a tool to run only after you explicitly approve a generation, upload, or task lookup request, not for general comparisons or pricing research about other video tools.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill advertises and documents capabilities that require environment access, local file read/write, network access, and shell execution, but it does not declare any permissions. This undermines least-privilege controls and informed consent because the agent may access credentials, write downloaded files, and invoke scripts without an explicit permission boundary.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding
The documented behavior extends beyond a narrowly scoped Seedance 2.5 text-to-video skill into generic model discovery, media upload, task management, account-related queries, and interactive API-key initialization/browser opening. This mismatch increases the chance of overbroad invocation and unexpected sensitive actions, especially where user credentials, wallet/account data, and local/browser side effects are involved.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The skill contains extremely broad activation keywords covering many brands, platforms, and generic comparison or migration intents, making accidental or manipulative triggering more likely. Overbroad routing can cause the agent to invoke a networked, file-writing, task-submitting skill when the user only asked for general information or tool comparison.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The applicable-user section is so broad that it effectively invites invocation for almost any video-generation-related query, without constraints on when execution is appropriate. In context, this is more dangerous because the skill can submit remote jobs, upload media, store task IDs, and download files, so mistaken invocation has tangible cost and privacy consequences.

Missing User Warnings

Low
Confidence
72% confidence
Finding
The documentation states that tasks are automatically saved and completed videos downloaded locally, but it does not prominently warn about where files are written, retention, naming/overwrite behavior, or possible exposure of generated content on shared systems. Even if the default directory is later mentioned, the lack of an upfront warning reduces informed consent for local side effects.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.