T08 · Insecure Dependencies
- Location
SKILL.md:136- Finding
Unpinned Dependency Installation Bypasses System Package Protections
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a real Toutiao auto-publisher that is mostly disclosed, but it can post publicly through an authenticated Chrome session without a final approval step.
Install only if you are comfortable with an automation tool that can publish to a live Toutiao account through your logged-in browser. Use a dedicated Chrome profile, close unrelated tabs, disable remote debugging after use, review the full final text yourself, avoid running it with no content, and prefer a virtual environment with pinned dependencies instead of the documented system-wide pip command.
SKILL.md:136Unpinned Dependency Installation Bypasses System Package Protections
toutiao_publish.py:229Publishing Workflow Exposes an Authenticated Primary Browser Through Chrome DevTools Protocol
toutiao_publish.py:213Short User Posts Are Silently Modified Before Automatic Publication
The documented purpose understates the actual behavior: the skill can publish default content without explicit user-provided text, upload images, and attach to an existing Chrome remote-debugging session to reuse the user's authenticated state. That mismatch is dangerous because users and reviewers may authorize what appears to be a simple posting tool without realizing it can perform live account actions through an already logged-in browser session.
The script performs a real publish action on the user's logged-in Toutiao account by directly clicking the final 发布 button, but it does not require an explicit user confirmation immediately before posting. Because it reuses an existing Chrome session via CDP on localhost:9222, any invocation of this skill can cause unintended account actions under the user's identity, making accidental or unauthorized posting significantly easier.
The skill declares no explicit tool scope or permissions even though its documented behavior includes reading local files via the -f/--file option. Missing scope declarations reduce transparency and safety review effectiveness, making it easier for a publishing skill to access local content without a clearly declared boundary.
The skill description does not prominently warn that it will perform a real external side effect: publishing content to a live Toutiao account and optionally uploading images. Without an explicit live-action warning, users may invoke the skill casually and trigger irreversible or reputationally harmful account activity.
The skill instructs users to enable Chrome remote debugging and reuse an existing login session, but does not provide a clear privacy or security warning about the risks of exposing an authenticated browser context. Remote debugging can grant broad access to browsing state, cookies, and authenticated actions, so omission of this warning materially increases the chance of unsafe use.
The default content explicitly states that the AI is freely exploring and has successfully published using the owner's account, which normalizes autonomous posting under someone else's identity. In the context of an auto-publishing skill that reuses the local logged-in browser session, this language increases concern because it evidences and encourages non-consensual or insufficiently supervised account use.
No suspicious patterns detected.