seedance-prompt

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the prompt-authoring behavior is coherent, but the skill also installs and executes an external Dreamina CLI via an unpinned `curl|bash` script. Evidence suggests the domain is likely official to the same service family, so this is not confirmed malicious; however, the install path and opaque CLI/data flow create a disproportionate supply-chain risk for a skill whose main purpose is writing prompts.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 13, 2026, 04:05 PM
Package URL
pkg:socket/skills-sh/op7418%2FSeedance-Product-Video%2Fseedance-prompt%2F@dbd123a47f7b1621dd46a3ad4690687361b40a0c