Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md - `scripts/search-seedance-readme.mjs` — keyword search against upstream README prompt entries via GitHub raw URLs
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent prompt-library helper with an optional GitHub README search script and no evidence of hidden, destructive, persistent, or credential-seeking behavior.
Before installing, be aware that the optional script contacts GitHub to retrieve the upstream prompt README files, and the skill may produce Chinese and English prompt variants unless you ask for one language only.
Referenced artifact was not completely inspected
- `scripts/search-seedance-readme.mjs` — keyword search against upstream README prompt entries via GitHub raw URLs
Without declared permissions the skill's intent is opaque and cannot be validated.
The description states the skill provides 'bilingual output,' which can be read as a default language behavior rather than a user-selected option. The policy allows locale constraints only when the user is offered a language choice or the constraint is clearly justified; that opt-in is not stated here.
The line says an optional 'CN + EN' pair may be returned 'when bilingual output helps,' which authorizes language switching based on the skill's judgment instead of explicit user preference. That can violate language/locale policy if users are not given a choice or opt-in.
The instruction says to provide both Chinese and English if the user may generate in either interface, which imposes a language behavior without explicit user choice. This can violate locale/language policy because it defaults to multilingual output based on inference rather than an opt-in or stated preference.
No suspicious patterns detected.