Back to skill

Security audit

抖音私信发送

Security checks for vulnerabilities and agentic risk

Overview

This skill is meant to send Douyin private messages, but it can act through a live account without a final confirmation and retains or reuses sensitive session data in ways users should review carefully.

Review this skill before installing. Use it only if you are comfortable with an agent operating a logged-in Douyin session, and require manual confirmation of the account, recipient, and exact message before sending. Avoid using the bundled script as-is because it hard-codes a local browser profile and writes screenshots that may expose private messages. Prefer a pinned dependency version or manually provide the Douyin display name instead of installing another skill dynamically.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:76
Finding

JavaScript Injection Through Unescaped Message Content

Content
View full analysis
{ var msg = '<消息内容>'; var inputs = document.querySelectorAll('[contenteditable=\"true\"]'); for(var input of inputs) { var rect = input.getBoundingClientRect(); if(rect.width > 0 && rect.height > 0) { input.focus(); for(var i=0; i
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:29
Finding

Unpinned Third-Party Skill Installation

Content
View full analysis
The relationship-management Skill is not installed. Should it be installed from ClawHub? Say "yes" to install it, or provide the recipient's Douyin display name directly. If the user agrees, execute: ```bash clawhub install person-relation-manager --workdir ~/.openclaw/workspace ``` ``` ### Technical Analysis The command installs a third-party Skill by mutable package name without selecting an audited version or verifying a cryptographic integrity digest. Consequently, the content installed during a future invocation may differ from the content that existed when this Skill was reviewed. Installing the dependency into the Agent workspace expands the trusted instruction and executable-code surface. User consent to installation does not address package substitution, publisher compromise, malicious updates, or changes introduced after this audit. ### Attack Path 1. The requested relationship-management Skill is unavailable locally. 2. The current Skill prompts the user to approve installation. 3. The Agent runs the unpinned `clawhub install` command. 4. ClawHub resolves whichever release is current at installation time. 5. A compromised, replaced, or malicious release is installed into the Agent workspace. 6. The Agent subsequently loads or executes the newly installed Skill with the permissions available to the workspace. ### Impact Assessment The precise impact depends on the installed package's behavior and the Agent's permissions. A malicious dependency could potentially: - Introduce hostile instructions into later Agent interactions. - Access files or tools exposed to installed Skills. - Manipulate contact-resolution results ...[truncated 328 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/send_douyin_dm.mjs:21
Finding

Hard-Coded Browser Profile Path Creates Unsafe Session Coupling

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/send_douyin_dm.mjs:41
Finding

Persistent Screenshots May Disclose Private Conversation Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill directly automates an irreversible external action—sending a private message—without requiring a final explicit confirmation of recipient and content immediately before submission. This is dangerous because a wrong search result, incorrect nickname resolution, or misunderstood prompt can cause unintended communication from the user's account, with social, privacy, and reputational consequences.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger description includes broad phrases such as sending a message or mentioning 'douyin send message', which can cause the skill to activate from ambiguous user requests that do not clearly authorize a Douyin private message action. Because the skill performs a real external action on the user's logged-in account, overbroad triggering increases the risk of unintended message sending.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example trigger '给 xxx 发消息' is highly generic and does not constrain the action to Douyin, making accidental invocation likely when the user simply wants to draft, discuss, or send a message through another channel. In this skill's context, accidental activation is more dangerous because execution results in an actual private message being sent through a live browser session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill does not clearly disclose that it will access and operate within the user's authenticated Douyin web session, including searching accounts, opening profiles, and interacting with private-message UI elements. This insufficient disclosure increases privacy and account-operation risk because users may not realize the skill is acting in a live signed-in context and potentially exposing sensitive on-screen data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script launches Playwright with a hard-coded persistent browser profile path, causing it to reuse whatever authenticated Douyin session and browser state already exist on that machine. In the context of an automation skill that sends private messages, this is dangerous because it can act as the logged-in user without explicit disclosure or isolation, and it also tightly binds the skill to a specific local user environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script uses a persistent browser profile containing local authenticated session data but does not clearly disclose that behavior to the user. In practice, this allows the automation to perform actions as whoever is already logged in, which is especially sensitive for direct messaging because it can impersonate the local account holder and access private account context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script sends the private message immediately by pressing Enter, with no confirmation prompt or last-chance review before an irreversible external action. In a messaging skill, this increases the risk of accidental delivery, misuse, or sending messages through an unintended authenticated account.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script saves a post-send screenshot after transmitting the message, which can capture private message contents, recipient identity, and surrounding chat history. Because the skill's purpose is message sending rather than record collection, this introduces avoidable exposure of sensitive communications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file's human-facing documentation and runtime messages are written only in Chinese, which imposes a specific language on users without indicating that it is language-specific or optional. This matches the policy concern for forced language or locale in natural-language content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

When the target user is not found, the script saves a local screenshot for debugging even though the declared purpose is only to send a Douyin DM. That screenshot may capture account information, contact lists, or other page contents unrelated to the requested action, creating unnecessary data retention.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.