seedance-submitter

Warn

Audited by Socket on May 13, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s media-generation purpose is coherent, but its actual trust boundary is not. The main issue is opaque routing through an unspecified PostPlus Cloud service, with local scripts and likely credentials/media forwarded to endpoints that are not identified or verifiable from the provided material. This is not confirmed malware, but the install/execution trust and data-flow integrity are too unclear to classify as benign.

Confidence: 84%Severity: 68%
AnomalyLOW
_postplus_shared/40-creative/image-batch-runner/scripts/_shared.mjs

No direct malicious/backdoor behavior is evident in this code fragment. The module’s main security exposure is design-level trust boundaries: it can read/write/create directories for caller-influenced filesystem paths without root confinement, and it forwards caller-controlled URLs to hosted generation/download bridge functions without visible URL allowlisting/validation. Additionally, it can delegate uploading arbitrary local files via uploadLocalMedia. These factors raise the risk of SSRF, arbitrary file read/write, and potential local file exfiltration if upstream authorization/input validation is insufficient.

Confidence: 63%Severity: 62%
Audit Metadata
Analyzed At
May 13, 2026, 07:54 PM
Package URL
pkg:socket/skills-sh/PostPlusAI%2Fpostplus-skills%2Fseedance-submitter%2F@81d3314c605ee1a8dabc39d0f3a6734334c9f8a1