seedance-antislop
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to process and rewrite user-provided prompts, creating an inherent attack surface for indirect prompt injection where malicious instructions could be embedded in the input data.
- Ingestion points: User-supplied prompt text provided for Seedance 2.0 rewriting (identified in SKILL.md).
- Boundary markers: The instructions do not define explicit delimiters or 'ignore embedded instructions' warnings for the input data.
- Capability inventory: The skill is limited to prompt text transformation and returning revised output; no file-writing, network operations, or shell execution capabilities were identified.
- Sanitization: There are no explicit sanitization or filtering steps for the ingested user content.
- [METADATA_POISONING]: The skill metadata contains a minor discrepancy between the author identifier ('Iamemily2050') and the repository owner/vendor ID ('Emily2040'). This inconsistency is noted but does not appear to facilitate deception regarding the skill's capabilities or safety.
Audit Metadata