seedance-submitter

Pass

Audited by Gen Agent Trust Hub on May 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The script _postplus_shared/00-core/shared-runtime/scripts/download_videos_from_manifest_with_ytdlp.mjs executes yt-dlp via python3 to download video outputs. This is a functional requirement for retrieving generated content.
  • [EXTERNAL_DOWNLOADS]: The skill downloads generated media from PostPlus Cloud storage and external sources as defined in the media production manifest.
  • [DATA_EXFILTRATION]: Local media files are uploaded to PostPlus Cloud for processing. This transmission is a core component of the skill's video generation workflow and targets the vendor's own infrastructure.
  • [SAFE]: The skill demonstrates secure practices by using schema validation, avoiding hardcoded credentials, and restricting operations to the PostPlus ecosystem. No unauthorized data access or persistence mechanisms were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
May 13, 2026, 07:52 PM