Back to skill

Security audit

OpenClaw Seedance Prompt Library

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent prompt-library helper with an optional GitHub README search script and no evidence of hidden, destructive, persistent, or credential-seeking behavior.

Before installing, be aware that the optional script contacts GitHub to retrieve the upstream prompt README files, and the skill may produce Chinese and English prompt variants unless you ask for one language only.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
- `scripts/search-seedance-readme.mjs` — keyword search against upstream README prompt entries via GitHub raw URLs

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description states the skill provides 'bilingual output,' which can be read as a default language behavior rather than a user-selected option. The policy allows locale constraints only when the user is offered a language choice or the constraint is clearly justified; that opt-in is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The line says an optional 'CN + EN' pair may be returned 'when bilingual output helps,' which authorizes language switching based on the skill's judgment instead of explicit user preference. That can violate language/locale policy if users are not given a choice or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction says to provide both Chinese and English if the user may generate in either interface, which imposes a language behavior without explicit user choice. This can violate locale/language policy because it defaults to multilingual output based on inference rather than an opt-in or stated preference.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.