Back to skill

Security audit

Seedance 2.5 视频生成

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a disclosed AI Hive Seedance 2.5 video generator, though its discovery keywords are broader than the actual video workflow.

Install only if you intend to use AI Hive for Seedance 2.5 video generation. Expect it to store an AI Hive API key if you run init, upload any media files you provide, potentially incur API charges, and save generated files locally. Avoid invoking it for unrelated competitor comparisons or generic ecommerce research despite the broad keywords.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Lp3

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding
The skill advertises significant capabilities including environment access, file read/write, network, and shell execution but does not declare permissions. This weakens user and platform visibility into what the skill can do and creates a risk of unintended data access, local file modification, or command execution beyond user expectations.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding
The skill claims to be narrowly focused on Seedance 2.5 video generation, but the detected behavior indicates it can act as a broader AI Hive OpenAPI client, including chat, image generation, model enumeration, and user-info queries. That mismatch is dangerous because users may authorize or invoke the skill under a limited-use assumption while it has access to broader account data and service actions.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The file implements a broad generic AI client with chat, image generation, model listing, uploads, and other capabilities that exceed the manifest’s stated Seedance 2.5 video-generation scope. In a skill ecosystem, scope expansion is dangerous because it grants users or orchestrators access to unexpected actions and data flows, increasing attack surface and enabling misuse through an ostensibly narrow skill.

Description-Behavior Mismatch

Low
Confidence
84% confidence
Finding
The skill exposes a user-info capability that is not described in the manifest and is unrelated to generating Seedance videos. Even if intended for convenience, it can reveal account metadata or wallet/billing information to workflows that only expected media generation, violating least privilege and surprising users.

Vague Triggers

Medium
Confidence
77% confidence
Finding
The skill description uses very broad trigger keywords covering many brands, platforms, and generic video-generation intents, increasing the chance the orchestrator activates this skill for loosely related requests. Overbroad activation can route users into a tool with networked execution, file handling, and API-key workflows they did not specifically request.

Vague Triggers

Medium
Confidence
79% confidence
Finding
The applicability section frames activation around vague search intent rather than precise functional boundaries, which can cause accidental or overly aggressive invocation. In the context of a skill that uploads media, stores task IDs, downloads files, and uses external APIs, mistaken activation expands exposure of user data and local resources.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.