Back to skill

Security audit

Seedance 图生视频

Security checks across malware telemetry and agentic risk

Overview

This is mostly a disclosed AI Hive Seedance image-to-video tool, but its activation/search scope is much broader than its actual purpose while it can upload local media and use a stored API key.

Review before installing. Use this only when you deliberately want selected media sent to AI Hive for Seedance image-to-video generation, and avoid treating it as a general competitor, ecommerce, pricing, or API research skill. Keep the API key in ~/.ai-hive/config.json protected, monitor generation costs, and avoid uploading private/customer assets unless AI Hive processing is acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill documentation describes capabilities that access environment variables, read/write local files, invoke shell commands, and make network requests, yet it declares no permissions. This weakens user consent and platform enforcement because the skill can handle API keys, upload local media, and persist files without an explicit permission boundary.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The skill is presented as a narrow Seedance image-to-video workflow, but the documented behavior extends to account queries, model enumeration, chat/multimodal operations, generic media generation, standalone uploads, and interactive API-key setup with local storage. This mismatch increases the risk of over-collection, unintended data transmission, and user consent bypass because users may invoke a much broader tool than they intended.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The file embeds a full generic AI Hive client with chat, image, video, model listing, upload, and task operations, while the advertised skill is a narrowly scoped Seedance image-to-video tool. This scope mismatch increases attack surface and allows callers to repurpose the skill for unrelated capabilities, undermining least privilege and trust in the manifest.

Context-Inappropriate Capability

Low
Confidence
85% confidence
Finding
The presence of a user-info endpoint allows the skill to inspect account details and balance, which is unrelated to image-to-video generation. Even if not exposed by the final skill CLI, retaining this capability in the implementation broadens what the code can do if invoked directly or reused incorrectly.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The top-level documentation explicitly describes a generic AI capability invocation tool, contradicting the specialized Seedance-only intent. This is a strong indicator that the implementation was adapted from a broader utility without fully constraining exposed behavior, which can mislead reviewers and enable misuse.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation text is so broad that it can match many generic video, marketing, and AI-tool queries unrelated to the narrow Seedance workflow. Overbroad triggering is dangerous because it can cause the skill to run in contexts where users did not intend file upload, external API use, or local output writing.

Vague Triggers

Medium
Confidence
82% confidence
Finding
Claiming suitability for broad competitor, pricing, migration, and API-search scenarios extends the skill far beyond a specific generation workflow. In ambiguous search/comparison contexts, the skill may be selected despite user intent being informational only, creating unnecessary exposure of files, credentials, or paid API actions.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The e-commerce platform and role coverage section is excessively expansive, making the skill eligible for many commerce and advertising queries that do not inherently request video generation. That broad scope increases accidental invocation risk in high-sensitivity commercial workflows where product assets, campaign materials, or customer data may be uploaded externally.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill documents automatic upload of user media to an external service and automatic download/storage of generated outputs locally, but it does not prominently warn users about these data flows. This is dangerous because sensitive images, videos, or commercial assets may be transmitted and persisted without clear informed consent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.