seedance-advanced

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is entirely instructional, serving as a technical guide for video production workflows. It provides parameters and best practices for using video generation models without introducing malicious code or configurations.
  • [COMMAND_EXECUTION]: The instructions include template commands for the higgsfield CLI (for generating video) and ffmpeg (for frame extraction). These are standard operational commands relevant to the skill's primary purpose and do not show evidence of shell injection or malicious intent.
  • [INDIRECT_PROMPT_INJECTION]: The skill specifically addresses the surface area where untrusted reference data (images, videos, audio) could influence model behavior. It provides specific prompt-engineering mitigations to ensure role isolation and prevent 'identity leaks' from reference media.
  • Ingestion points: Processes external media references (labeled @Image1, [Video 1], [Audio 1]) through the generation prompt in SKILL.md.
  • Boundary markers: Explicitly instructs the agent to use boundary language such as "ignore its performer, room, logo, and costume" to delimit the influence of reference files.
  • Capability inventory: Utilizes the higgsfield CLI for media generation and ffmpeg for local file processing.
  • Sanitization: Recommends strict role-binding syntax to ensure that reference data only influences specific aspects (e.g., rhythm or camera motion) of the output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 02:35 AM
Security Audit — agent-trust-hub — seedance-advanced