Back to skill

Security audit

Seedance 视频延长

Security checks across malware telemetry and agentic risk

Overview

The skill mostly performs disclosed AI Hive video-extension work, but its activation scope is much broader than that sensitive media-upload purpose.

Review this before installing if you work with private, client, or unreleased media. Only use it when you intentionally want AI Hive to receive the selected files, and prefer --no-download or a chosen output directory when you do not want automatic local result files. The publisher should narrow the trigger wording to Seedance video extension and add a clearer upfront data-handling notice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill documents capabilities that read environment variables, read/write local files, invoke shell commands, and access the network, yet it does not declare permissions or present explicit user-facing constraints. This creates a transparency and least-privilege problem: users and hosting platforms cannot accurately evaluate what the skill may access before activation, increasing the chance of unintended credential exposure, local file modification, or external data transfer.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The documented scope is narrowly framed as Seedance video extension, but the described behavior includes broader account queries, model discovery, chat/image/video functions, standalone upload, and browser-based API-key bootstrap with local config writes. This mismatch is dangerous because users may invoke the skill under the assumption of limited-purpose processing while it can access additional account data, perform broader network actions, and persist secrets locally.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The file is packaged as a dedicated Seedance video-extension skill, but the codebase embeds a general-purpose AI Hive client with broader capabilities than the manifest describes. This creates scope mismatch and increases the attack surface, making it easier for a skill consumer or downstream agent to invoke unintended functionality beyond the declared purpose.

Context-Inappropriate Capability

Low
Confidence
84% confidence
Finding
Exposing user-info and model-listing commands in a narrowly scoped media-extension skill unnecessarily reveals account metadata and available model inventory. In a skill context, this broadens information disclosure and enables reconnaissance that is unrelated to the advertised function.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
Including full text-chat and image-generation functions in a skill intended for fixed Seedance video extension materially expands what the skill can do if invoked directly. That mismatch weakens least-privilege boundaries and can let a caller use the skill as a more general AI broker than intended.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description contains extremely broad trigger terms covering many competing tools, platforms, business roles, and search intents, making accidental or irrelevant activation more likely. Over-broad matching is risky in a skill that uploads user media, stores task IDs, polls remote jobs, and downloads outputs, because it can cause data to be sent to external services in contexts where the user did not intend to use this provider.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The introduction further broadens applicability without clear constraints, exclusions, or user warnings, which increases the chance that the skill is selected for loosely related video, e-commerce, or migration discussions. In this context, ambiguous activation matters because the skill performs external uploads and automated downloads, so mistaken invocation can unnecessarily expose sensitive media and project content.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill omits a prominent warning that user-supplied media and generated outputs are transmitted to external AI Hive services, that tasks are stored remotely, and that results may be downloaded automatically to local disk. This is a meaningful privacy and data-handling issue because users may provide proprietary footage, client assets, or personal media without understanding the external processing and local persistence involved.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.