byted-seedance-video-generate

Fail

Audited by Snyk on Aug 19, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill explicitly tells the agent to have the user provide API keys and to write those environment variables into a workspace file (and retry), which requires the LLM to handle and output secret values verbatim, creating an exfiltration risk.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The runtime path scripts/video_generate.py ingests outsider-authored free text via item["prompt"] (from --prompt) and sends it in _build_content() as {"type":"text","text": prompt} to the external /contents/generations/tasks endpoint.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.70). The skill instructs the agent to write/append API keys into an environment variable file in the workspace and "make the environment variable effective," which directs the agent to modify files and change the runtime environment on the host machine.

Issues (3)

W007
HIGH

Insecure credential handling detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Aug 19, 2026, 05:30 PM
Issues
3
Security Audit — snyk — byted-seedance-video-generate