Back to skill

Security audit

steampunk-transform-video-gen-seedance2-0

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed WeryAI video-generation skill with expected API-key, network, paid-generation, and optional image-upload behavior, but users should verify the model and avoid local paths unless intentional.

Install only if you trust this publisher and WeryAI with your WERYAI_API_KEY, paid credits, prompts, and any images you provide. Before running generation, confirm the JSON uses model SEEDANCE_2_0, review the full prompt/settings, and use public HTTPS image URLs unless you intentionally want a specific local file uploaded to WeryAI.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding
The skill claims to be narrowly constrained to steampunk-only Seedance 2.0 generation, but its documented behavior admits broader video generation features including model listing, polling arbitrary jobs, and possible local file upload to WeryAI. That mismatch is dangerous because users may trust the narrower description and unknowingly permit broader data handling or model usage than expected, especially when local images can be read and uploaded.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The documentation explicitly describes a local-file path that causes the script to read files from disk and upload them to a remote endpoint, which expands capability beyond a simple steampunk video-generation skill. In an agent setting, this can enable unintended exfiltration of local user files if prompts or wrappers permit file-path input without strong consent and scoping.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The file documents disk-read and remote upload behavior that is not clearly necessary for the advertised purpose and could be abused to access and transmit local content. Even if intended for convenience, hidden or under-justified file access is risky in agent environments because users may not realize a local path will trigger outbound transfer.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The script implements a general-purpose WeryAI video generation CLI with text-to-video, image-to-video, multi-image, status, and model enumeration workflows, while the skill metadata claims a narrowly scoped steampunk Seedance 2.0 transformation purpose. This capability mismatch can let an agent use the skill for arbitrary video generation outside user and platform expectations, undermining least privilege and increasing misuse risk even though it is not an exploit primitive by itself.

Context-Inappropriate Capability

Low
Confidence
84% confidence
Finding
The models registry call exposes discovery of all available video models even though the skill is described as a single-purpose steampunk transformation tool. While low severity, this broadens the skill's operational scope and can facilitate pivoting to unintended model use by revealing options that should be outside the skill's contract.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.