seedance

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, and it uses official Ark-style endpoints by default, but it relies on a non-official third-party CLI and forwards `ARK_API_KEY` plus user media through that code. The optional custom endpoint setting further weakens data-flow integrity by allowing credential/media routing to arbitrary servers. This is not confirmed malware, but it is higher-risk than a first-party or direct official API integration.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
Sep 4, 2026, 10:36 AM
Package URL
pkg:socket/skills-sh/zjandrew%2Fseedance-cli%2Fseedance%2F@e2c84e01a6d52138c8e447e076adfd96daac2f92290b7281e9ec1179c2eafaf3
Security Audit — socket — seedance