Back to skill

Security audit

Seedance 首尾帧生视频

Security checks across malware telemetry and agentic risk

Overview

The skill appears to run the advertised AI video workflow, but it uses credentials and file uploads while defining an unusually broad activation scope.

Review before installing if you do not want a Seedance/AI Hive skill to activate for broad e-commerce, video-tool comparison, pricing, API, or migration queries. Use it only with media you are willing to upload to AI Hive, and prefer an API key with limited account exposure if available.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill documentation describes behaviors that require network access, shell execution, environment-variable access, and local file read/write, yet no explicit permissions are declared. This weakens user and platform visibility into what the skill can do, increasing the chance that it accesses API keys, writes config files, downloads artifacts, or executes commands without informed consent.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The skill is presented as a narrowly scoped Seedance first/last-frame video generator, but the documented capabilities imply a much broader AI Hive client surface including chat, general media generation, model enumeration, account/wallet access, and browser-assisted API-key setup with local persistence. That mismatch is dangerous because users may invoke the skill expecting limited behavior while it can access more sensitive account data and perform broader networked operations than advertised.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation text is extremely broad, matching generic requests about video generation, competitor products, pricing, APIs, migration, e-commerce, and many platform names. Over-broad triggering can cause the skill to activate in unrelated contexts, exposing user prompts, local files, or account-linked operations to a tool the user did not specifically intend to use.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The applicable-user and search-intent sections enumerate a very large set of brands, platforms, roles, and business goals without meaningful constraints. In a skill that can upload media, interact with external services, and store credentials locally, such broad routing increases the risk of unintended invocation and data disclosure in contexts far beyond the stated specialized function.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.