Back to skill

Security audit

Seedance 文生视频

Security checks across malware telemetry and agentic risk

Overview

This appears to be a real AI Hive Seedance video-generation skill, but its activation scope and data-transfer/credential handling are broad enough that users should review it before installing.

Install only if you intend to use AI Hive/Seedance for paid video generation. Avoid using sensitive prompts or private media unless you accept sending them to AI Hive and its storage flow, prefer the protected config file or environment variable for the API key, and do not rely on this skill for neutral comparisons or unrelated vendor pricing searches.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill documentation exposes capabilities to read environment/config, write files, invoke shell commands, and make network requests, yet it declares no permissions. This undermines informed consent and review because users and orchestrators may invoke a skill with broader local and external access than its manifest suggests.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The skill claims to be narrowly scoped to Seedance text-to-video generation, but the documented/runtime behavior includes broader AI Hive operations such as generic media upload, model catalog access, account/wallet retrieval, and other generation pathways. This scope expansion can cause users or agents to authorize actions and data flows they did not intend, increasing the chance of secret exposure, privacy leakage, or misuse of paid APIs.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The file embeds a broad generic AI client and helper commands far beyond the advertised Seedance text-to-video purpose, including chat, image generation, model enumeration, user-info lookup, and arbitrary media upload. In an agent-skill context, this expands the callable attack surface and can let a user or orchestrator invoke unintended capabilities, increasing the risk of data exposure, billing abuse, and policy bypass.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The module docstring presents the code as a universal AI capability tool rather than a narrowly scoped Seedance text-to-video skill. That mismatch is security-relevant because reviewers, policy engines, or agents may trust the skill metadata while the implementation retains broader powers than expected.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The description uses extremely broad trigger terms spanning many unrelated video tools, platforms, and comparison queries. Overbroad activation increases the likelihood that this skill is selected in contexts where users did not intend to upload content, use paid APIs, or interact with this provider at all.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The applicable-user section defines activation with generic terms and lacks boundary conditions. In an agent ecosystem, this can cause unintended invocation and silent routing of prompts or media to an external service, which is risky because the skill also performs uploads and task submission.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The related-tools section broadens matching to competitor names, migration, pricing, API access, and platform searches without clear constraints. This creates a prompt-routing risk where users seeking neutral information or another vendor may be steered into this skill's external workflow and data transfer path.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill describes automatic task submission, media upload, polling, and result download but does not prominently warn that user prompts, media, and metadata will be transmitted to an external service. This is a privacy and consent issue, especially for sensitive creative assets, personal media, or proprietary product materials.

Missing User Warnings

Low
Confidence
80% confidence
Finding
The initialization instructions tell users to create and supply an API key, including via command-line arguments, without warning that shell history, process listings, logs, or screenshots can expose secrets. This makes accidental credential leakage more likely, which could lead to unauthorized API usage and billing abuse.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.