seedance-copyright

Warn

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: MEDIUMMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: The author field in the YAML frontmatter ("Iamemily2050") is a deceptive variation of the established author name ("emily2040") and the repository URL provided ("https://github.com/Emily2040/seedance-2.0"). The use of "50" instead of "40" and the "Iam" prefix are red flags for typosquatting and impersonation.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted user-provided prompts for transformation.
  • Ingestion points: Processes user prompts mentioning named characters, franchises, or people (SKILL.md).
  • Boundary markers: Absent; the instructions do not define delimiters for user input or include warnings to the agent to ignore embedded instructions within the data being processed.
  • Capability inventory: None; this specific file defines text transformation rules without direct access to command execution or network operations.
  • Sanitization: Absent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 21, 2026, 07:30 AM
Security Audit — agent-trust-hub — seedance-copyright