seedance-copyright
Warn
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: MEDIUMMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
- [METADATA_POISONING]: The
authorfield in the YAML frontmatter ("Iamemily2050") is a deceptive variation of the established author name ("emily2040") and the repository URL provided ("https://github.com/Emily2040/seedance-2.0"). The use of "50" instead of "40" and the "Iam" prefix are red flags for typosquatting and impersonation. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted user-provided prompts for transformation.
- Ingestion points: Processes user prompts mentioning named characters, franchises, or people (SKILL.md).
- Boundary markers: Absent; the instructions do not define delimiters for user input or include warnings to the agent to ignore embedded instructions within the data being processed.
- Capability inventory: None; this specific file defines text transformation rules without direct access to command execution or network operations.
- Sanitization: Absent.
Audit Metadata