seedance

Warn

Audited by Socket on Jun 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s video-generation purpose broadly matches its capabilities, but it relies on transitive skill installation, an external CLI, and official-yet-risky remote install paths. Data flows to inference.sh and, in Studio mode, to BytePlus are disclosed and plausible, so this is not confirmed malware; the main concerns are supply-chain trust and credential/data forwarding through external tooling.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 12, 2026, 07:38 PM
Package URL
pkg:socket/skills-sh/qu-skills%2Fskills%2Fseedance%2F@001b93ba74d6932e284625af1265444857d59405055487fa1590cc1b4ee8dab3
Security Audit — socket — seedance