Back to skill

Security audit

Douyin Web Control

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent Douyin automation, but its install and launcher can run unreviewed code that controls an authenticated browser session.

Review before installing. Use a pinned, reviewed CLI revision in an isolated virtual environment, set DOUYIN_WEB_CLI or DOUYIN_CLI_ROOT to a trusted absolute path, and avoid running the wrapper from untrusted workspaces. Use isolated --profile or --home values, and require explicit confirmation before public actions or recording.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:16
Finding

Unpinned VCS Dependency Allows Upstream Code Substitution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:16-21 and scripts/douyin-web:43-50
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code

SKILL.md:16-21:

bash
If the CLI is not installed, install it first:

python3 -m pip install "git+https://github.com/billwang233/douyin-web-cli.git"
python3 -m playwright install chromium
douyin-web --help

scripts/douyin-web:43-50:

bash
Set one of:
  DOUYIN_WEB_CLI=/path/to/douyin-web
  DOUYIN_CLI_ROOT=/path/to/repo

Or install the harness:
  python3 -m pip install "git+https://github.com/billwang233/douyin-web-cli.git"
  python3 -m playwright install chromium

Technical Analysis

The installation command retrieves the package directly from the Git repository's moving default branch. It does not specify an immutable commit hash, a signed release, a fixed package version, or an integrity digest.

Consequently, the code executed by pip can change after this Skill has been reviewed. Installation may run attacker-controlled package build or setup logic, and subsequent CLI invocations execute the installed code. The use of HTTPS protects the transport channel but does not establish that the retrieved revision is the one that was audited.

Attack Path

  1. An attacker compromises the upstream repository, a maintainer account, or the repository's default branch.
  2. The attacker adds malicious package installation or runtime code.
  3. A user or Agent follows the documented installation command.
  4. pip retrieves the current, compromised repository revision and executes its build or installation process.
  5. The malicious package subsequently runs as the invoking user whenever the CLI is used.

Impact Assessment

Exploited code would run with the operating-system privileges of the user invoking pip or the CLI. Within that privilege boundary, it could access files available t ...[truncated 562 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the Git dependency to a reviewed immutable commit, for example by using a full commit SHA rather than the default branch.
  • Prefer a versioned, signed release distributed through a trusted package registry.
  • Where package installation supports it, use a lock file and verify cryptographic hashes for downloaded artifacts.
  • Record the expected repository, version, commit digest, and verification procedure in SKILL.md.
  • Install the dependency into an isolated virtual environment with the minimum permissions required.
  • Review dependency changes before updating the pinned revision.
  • Avoid running installation as root or with elevated privileges.

T07 · Tool Hijacking and Spoofing

Warning
Location
scripts/douyin-web:4
Finding

Workspace-Ancestor Tool Discovery Can Execute an Attacker-Controlled CLI

Content
View full analysis

Vulnerability Details

File Location: scripts/douyin-web:4-30
Vulnerability Type: Unsafe local tool discovery and execution
Risk Level: Medium

Vulnerable Code

bash
find_repo_root() {
  local dir
  dir="${DOUYIN_CLI_ROOT:-${PWD}}"
  while [[ "$dir" != "/" ]]; do
    if [[ -x "$dir/bin/douyin-web" ]] || [[ -f "$dir/agent-harness/setup.py" && -d "$dir/agent-harness/cli_anything/douyin_web" ]]; then
      printf '%s\n' "$dir"
      return 0
    fi
    dir="$(dirname "$dir")"
  done
  return 1
}

if [[ -n "${DOUYIN_WEB_CLI:-}" ]]; then
  exec "$DOUYIN_WEB_CLI" "$@"
fi

if repo_root="$(find_repo_root)"; then
  if [[ -x "$repo_root/bin/douyin-web" ]]; then
    exec "$repo_root/bin/douyin-web" "$@"
  fi
  if [[ -f "$repo_root/agent-harness/setup.py" ]]; then
    (
      cd "$repo_root/agent-harness"
      exec python3 -m cli_anything.douyin_web "$@"
    )
  fi
fi

Technical Analysis

When DOUYIN_CLI_ROOT is not set, executable discovery begins at the current working directory and traverses every parent directory. The first directory containing an executable bin/douyin-web, or a matching Python harness layout, is treated as a trusted repository.

The selected executable or Python module is then run without checking its canonical path, ownership, permissions, signature, or cryptographic digest. This means that repository contents controlled by an attacker can override a legitimate globally installed CLI merely because the wrapper is invoked from within that repository.

Quoting of variables prevents ordinary shell argument injection, but it does not address the trust-boundary issue: the executable itself may be attacker-controlled. The explicit DOUYIN_WEB_CLI and ambient PATH fallbacks similarly rely on the caller's environment being trustworthy.

Attack Path

  1. An attacker supplies a repository or workspace containing a malicious executable at ...[truncated 1358 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove automatic current-directory and ancestor-directory discovery for security-sensitive executables.
  • Require DOUYIN_CLI_ROOT or DOUYIN_WEB_CLI to identify an explicitly configured, trusted installation.
  • Resolve configured paths with a canonicalization mechanism and ensure they reside beneath an approved installation directory.
  • Validate file ownership and reject executables or module directories writable by untrusted users.
  • Verify the executable or package against a pinned cryptographic digest or trusted signature before execution.
  • Prefer an isolated, version-pinned virtual environment and invoke its interpreter and module through fixed absolute paths.
  • If PATH lookup must remain available, document that only a sanitized trusted PATH is supported and reject unsafe writable path entries.
  • Do not run the wrapper with elevated privileges when processing untrusted workspaces.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This section documents commands that can cause externally visible actions or persist user data, including liking, following, favoriting, opening share flows, submitting comments/danmaku, taking screenshots, and recording screen/audio, but it does not require confirmation gates, dry-run defaults, or explicit warnings about side effects. In an agent-operated context, that omission increases the risk of unintended public interactions, privacy exposure, or recording/storage of sensitive content when the tool is invoked automatically.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file content, headings, and command descriptions are all presented in Chinese, and there is no note offering an alternative language or documenting that the skill is intentionally limited to Chinese users. Per the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.