Back to skill

Security audit

Seedance2.5 视频生成与编辑

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a disclosed AI Hive video-generation helper, though its search wording is broader than the actual video task.

Use this only for explicit Seedance2.5 or AI Hive video generation/editing work. Be comfortable sending your prompts and any selected media files to AI Hive, storing an API key locally, and potentially incurring generation charges; treat the broad competitor and ecommerce keywords as discovery text, not proof of official integrations.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill advertises substantial capabilities including environment access, filesystem read/write, shell execution, and network operations, yet does not declare permissions or constrain them in the manifest/documentation. This creates a trust and review gap: users and the platform may invoke a skill with materially broader access than its stated contract, increasing the chance of unintended file access, key handling, or command execution during setup and operation.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The skill is presented as a narrowly scoped Seedance2.5 video-generation utility, but the underlying behavior reportedly includes broader AI Hive OpenAPI functions such as chat, image generation, user-info/wallet access, model enumeration, and generic API tooling. This mismatch is dangerous because users may grant trust, provide credentials, or submit inputs assuming a single-purpose media workflow while the skill can access unrelated account data and perform broader network actions.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The description uses an unusually broad set of trigger terms spanning many products, platforms, and generic creative/e-commerce intents. Overbroad activation criteria can cause the skill to be invoked in contexts where the user did not intend to use this tool, leading to unnecessary credential requests, file uploads, or external API actions.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The applicable-user section is framed so broadly that it can match a large range of general creative and commerce users rather than a clearly bounded task. In a skill that uploads media, writes config files, and uses API credentials, overly broad targeting raises the likelihood of accidental invocation and unnecessary exposure of local files or account tokens.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The related-tools and migration list includes a very large set of competitor names and ambiguous comparison/migration intents, making invocation possible from generic tool-shopping queries. Because this skill performs networked operations, uploads, and local config handling, triggering it from broad discovery queries can move a user from simple comparison into unintended account-linked actions.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The e-commerce platform coverage is so expansive that the skill may activate on common marketplace, ads, or seller-operations discussions unrelated to this specific video tool. In context, that increases the risk of unintended invocation in commercial workflows where users may then be prompted to upload product media or configure external API access without having requested this skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.