Back to skill

Security audit

Seedance 视频生成

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed AI Hive Seedance video-generation wrapper, with some broad activation wording users should treat carefully.

Install only if you intend to use AI Hive for Seedance video generation. Expect selected media files to be uploaded to AI Hive/object storage, generated results to be downloaded locally, and API usage to potentially incur costs. Keep the API key private and be aware the skill may be suggested for broad AI-video or e-commerce queries where you may only want research, not generation.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding
The skill documentation exposes capabilities for environment access, file read/write, network access, and shell execution, but does not declare permissions or clearly constrain them. In an agent setting, this reduces transparency and can cause the skill to be invoked with broader authority than users or policy expect, increasing the risk of credential exposure, unintended file modification, or arbitrary external requests.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding
The stated purpose is Seedance video generation, but the described behavior extends into account querying, wallet/balance access, generic chat/image generation, standalone uploads, and browser-based API key setup with local credential storage. This mismatch is dangerous because it creates hidden or surprising functionality that can collect credentials, enumerate user account data, or perform actions outside the user’s likely intent when activating a narrowly branded skill.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill uses extremely broad activation keywords spanning many video tools, e-commerce platforms, and generic creative intents, which can cause the agent to trigger this skill for loosely related requests. Overbroad triggering is dangerous because it increases the chance of unnecessary API-key collection, file upload, network activity, or task submission in contexts where the user did not specifically request this tool.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The '适用对象' section defines activation scope using expansive search terms with no limiting conditions, reinforcing a trigger surface much wider than the actual core task. In context, this makes the skill more dangerous because the skill also performs networked operations, local file writes, and API-key handling, so accidental activation can lead to privacy-impacting or cost-incurring side effects.

Static analysis

No suspicious patterns detected.