Back to plugin

Security audit

Seedance Story Director

Security checks for vulnerabilities and agentic risk

Overview

The plugin appears aligned with its video-generation purpose, but users should notice that it uses paid external model APIs, stores reusable local project assets, and has a minor dependency-lockfile mismatch to review.

Install only if you are comfortable sending story/reference content to the configured model providers and using their API quota. Keep keys in environment variables, review the output/workspace directory for retained assets, and check the lockfile/dependencies before running pnpm install.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
dist/src/config.js:61
Evidence
apiKey: [REDACTED] || process.env[apiKeyEnv],

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
dist/src/director.js:267
Evidence
apiKey: [REDACTED],

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
dist/src/service.js:271
Evidence
const apiKey = [REDACTED](prepared.config);

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/config.ts:72
Evidence
apiKey: [REDACTED] || process.env[apiKeyEnv],

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/director.ts:322
Evidence
apiKey: [REDACTED],

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/service.ts:376
Evidence
const apiKey = [REDACTED](prepared.config);