seedance-submitter
Pass
Audited by Gen Agent Trust Hub on May 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The script _postplus_shared/00-core/shared-runtime/scripts/download_videos_from_manifest_with_ytdlp.mjs executes yt-dlp via python3 to download video outputs. This is a functional requirement for retrieving generated content.
- [EXTERNAL_DOWNLOADS]: The skill downloads generated media from PostPlus Cloud storage and external sources as defined in the media production manifest.
- [DATA_EXFILTRATION]: Local media files are uploaded to PostPlus Cloud for processing. This transmission is a core component of the skill's video generation workflow and targets the vendor's own infrastructure.
- [SAFE]: The skill demonstrates secure practices by using schema validation, avoiding hardcoded credentials, and restricting operations to the PostPlus ecosystem. No unauthorized data access or persistence mechanisms were detected.
Audit Metadata