seedance-submitter

Warn

Audited by Socket on May 5, 2026

3 alerts found:

Anomalyx3
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities mostly match its stated purpose, but its real data flow is insufficiently transparent. It uploads local assets and prompt content through opaque local scripts to an unspecified hosted capability, creating medium risk of third-party routing or unreviewed credential handling even though no overtly malicious behavior is shown.

Confidence: 83%Severity: 58%
AnomalyLOW
_postplus_shared/00-core/shared-runtime/scripts/lib/hosted_media_generation_bridge.mjs

No clear evidence of intentional malware/backdoor behavior is present in this module alone. However, it provides powerful capabilities: it can read arbitrary local files (via resolved localFilePath) and write arbitrary files (via resolved outputPath) using remote-provided base64 content, with minimal validation/containment. If upstream callers or the bridge supply untrusted paths/urls/content, this can enable data exfiltration (upload) and unintended file overwrite or persistence-like impact (download).

Confidence: 62%Severity: 63%
AnomalyLOW
_postplus_shared/40-creative/image-batch-runner/SKILL.reference.md

SUSPICIOUS: the skill’s capabilities broadly match its stated image-batch purpose, but the true network endpoints and trust boundary are opaque. Uploading local media and routing generation through internal aliases/local scripts without disclosing official provider domains creates medium risk around data flow integrity, though there is no strong evidence of outright malware or credential theft in the supplied text.

Confidence: 79%Severity: 58%
Audit Metadata
Analyzed At
May 5, 2026, 05:06 PM
Package URL
pkg:socket/skills-sh/PostPlusAI%2Fpostplus-skills%2Fseedance-submitter%2F@f4447e0b29563e0fdcb2a9d291a3201d318dae60