skills/mblode/video-studio/seedance/Gen Agent Trust Hub

seedance

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided film ideas, story descriptions, and existing prompts to generate complex JSON structures and prompts for AI video models.
  • Ingestion points: SKILL.md (ingests user-provided story ideas and prompts for fixing/improvement).
  • Boundary markers: No explicit delimiters or "ignore embedded instructions" markers for user-provided ideas are defined in the ingestion phase.
  • Capability inventory: File system write operations (stills.json, shots.json) and local command execution (node dist/cli.js).
  • Sanitization: Incorporates Zod-based schema validation via the vs tool to verify JSON structure, but does not perform sanitization or filtering on the natural language prompt content.
  • [EXTERNAL_DOWNLOADS]: Fetches prompt optimization skill metadata and updates from ByteDance's official Volcengine (BytePlus) documentation infrastructure.
  • [COMMAND_EXECUTION]: Executes the project's CLI utility using node dist/cli.js to perform film validation, character synchronization, and file generation tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:00 PM
Security Audit — agent-trust-hub — seedance