byted-seedance-video-generate
Fail
Audited by Snyk on Aug 19, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill explicitly tells the agent to have the user provide API keys and to write those environment variables into a workspace file (and retry), which requires the LLM to handle and output secret values verbatim, creating an exfiltration risk.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The runtime path
scripts/video_generate.pyingests outsider-authored free text viaitem["prompt"](from--prompt) and sends it in_build_content()as{"type":"text","text": prompt}to the external/contents/generations/tasksendpoint.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 0.70). The skill instructs the agent to write/append API keys into an environment variable file in the workspace and "make the environment variable effective," which directs the agent to modify files and change the runtime environment on the host machine.
Issues (3)
W007
HIGHInsecure credential handling detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata