Back to skill

Security audit

Douyin Reverse Engineer

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches its video reverse-engineering purpose, but it should be reviewed because it uploads user videos to external services and relies on unpinned third-party skill dependencies.

Review before installing. Only use this with videos you are comfortable sending to Volcengine/Ark and with Douyin identifiers potentially handled through TikHub-related downloader code. Prefer pinned, reviewed dependency versions, add the missing douyin-downloader dependency explicitly, and run with a minimal environment containing only ARK_API_KEY rather than all local secrets.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Third-Party Skill Dependencies Create a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15–16
Vulnerability Type: Unpinned and mutable third-party skill dependencies
Risk Level: Medium

Vulnerable Code

bash
npx clawhub install doubao-video-analyzer
npx clawhub install video-downloader

Technical Analysis

The documented installation commands install third-party skills by name without specifying an exact version, immutable commit, cryptographic checksum, or verified artifact. Consequently, the code installed when users execute these commands can change after this skill has been reviewed.

These dependencies occupy security-sensitive positions in the workflow. video-downloader processes attacker-selectable URLs and creates local files, while doubao-video-analyzer runs with access to the process environment, including ARK_API_KEY, and processes local video content. reverse_video.py subsequently imports or executes dependency code as part of ordinary operation.

The project also imports a douyin-downloader component for Douyin URLs, although that runtime dependency is not declared in _meta.json or listed consistently among the documented prerequisites. This makes the complete dependency trust boundary less transparent.

No evidence was found that the currently reviewed project intentionally compromises these dependencies. The vulnerability is the absence of controls ensuring that future installed dependency content is the same content that was reviewed.

Attack Path

  1. An attacker compromises the registry account, publishing process, repository, or distribution entry associated with one of the named skills.
  2. The attacker publishes a malicious replacement or update under the trusted dependency name.
  3. A user follows the documented installation command, which resolves the current mutable release because no version or integrity constraint is present.
  4. The user invokes reverse_video.py.
  5. The project imports ...[truncated 996 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin each required skill to an exact reviewed version or, preferably, an immutable commit or content digest.
  2. Verify downloaded artifacts using cryptographic checksums or registry signatures before installation.
  3. Record trusted publishers, source repositories, versions, and expected hashes in the project documentation and metadata.
  4. Add every runtime dependency—including the douyin-downloader component used for Douyin URLs—to _meta.json and the installation documentation.
  5. Review dependency source code before approving version updates and use an automated lockfile or manifest-integrity check where supported.
  6. Run downloader and analyzer dependencies with least privilege, a restricted filesystem view, and only the environment variables they require.
  7. Avoid exposing ARK_API_KEY to downloader processes that do not need it; construct a minimal subprocess environment rather than inheriting the entire parent environment.
  8. Clearly disclose which external services receive video identifiers or video content, including TikHub and Volcano Engine Ark.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared purpose suggests narrow Douyin prompt reverse-engineering, but the documented behavior includes local file analysis, support for other platforms, external upload to Volcengine, and optional style-rewrite features. This mismatch is dangerous because users and orchestrators may authorize the skill under a much narrower trust assumption than what it actually does, leading to unintended data exfiltration or overbroad activation.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · reverse_video.py (reported line 368)May include surrounding context.

python
'--prompt', ANALYSIS_PROMPT,
        ]

        env = os.environ.copy()
        env['PYTHONIOENCODING'] = 'utf-8'

        try:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises executable behavior that uses environment variables, shell commands, and file read/write, but it does not declare an explicit tool/permission scope. That creates a trust and review gap: an agent or operator cannot easily constrain what the skill may access, increasing the risk of unintended file access, command execution, or secret exposure during use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases include broad terms like video analysis, prompt reverse-engineering, and game rewriting, which can match common user requests outside the intended scope. Overbroad triggering can cause the agent to invoke a powerful skill unnecessarily, exposing user content to download, local processing, or external AI services without clear need.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill documentation does not clearly warn that provided video URLs or local video files will be sent to an external AI analysis service. In this context, that omission is particularly risky because videos may contain sensitive, proprietary, or personal information, and users may not realize they are consenting to third-party transmission.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

Using npx clawhub install ... without pinning an exact version allows whatever package version is current at execution time to be fetched and run. This introduces a supply-chain risk where a compromised, malicious, or breaking upstream release can execute code on the host during installation or skill use.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This dependency installation command is also unpinned, so the environment may pull and execute an unexpected version of the referenced package. Because the installed skill appears to require shell tooling and media processing dependencies, compromise of that package could lead to arbitrary code execution or data theft.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This second unpinned package reference on the same line carries the same supply-chain exposure as the other npx examples. In a skill that orchestrates downloads and analysis of user-provided media, compromised dependencies could access local files, environment secrets, or downloaded content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The analysis prompt explicitly requires every ai_prompt to be '纯英文' / pure English. This is a natural-language locale policy constraint embedded in the code, and the file does not offer the user any language choice or opt-in for prompt language.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata presents itself as Douyin-focused, but the code broadens scope to arbitrary video platforms via yt-dlp-based downloading. This hidden capability changes the trust boundary and may cause users to provide URLs or content under inaccurate assumptions about what the skill can access and process.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · reverse_video.py (reported line 146)May include surrounding context.

python
cmd = [sys.executable, script_path, url, resolution, output_dir]
    print(f'[下载] 调用 video-downloader (yt-dlp) ...')

    result = subprocess.run(
        cmd,
        capture_output=True,
        timeout=600,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code path performs upload-based analysis of local video but the CLI surface does not provide an explicit warning or consent checkpoint before transmitting content to an external AI service. In a tool that accepts local files, this is especially risky because users may assume processing stays on-device while sensitive recordings are actually sent off-host.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code reads ARK_API_KEY and sends local video content to external Ark services for analysis, but that outbound transfer is not clearly disclosed by the skill's stated purpose. Uploading user-provided local media to a third-party API without prominent advance notice can expose sensitive content, credentials-backed billing, and compliance/privacy risks.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · reverse_video.py (reported line 372)May include surrounding context.

python
env['PYTHONIOENCODING'] = 'utf-8'

        try:
            result = subprocess.run(
                cmd,
                capture_output=True,
                timeout=600,  # 10分钟超时(上传+处理+分析可能较慢)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest says the skill reverse-engineers prompts and storyboards, but the implementation also performs style transformation and content rewriting into game/anime and Rusty Lake variants. That undisclosed generative modification materially changes the nature of processing and could surprise users who expected analysis rather than creative rewriting.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description is written entirely in Chinese and does not indicate any language choice or opt-in. This can violate a language/locale policy when a skill implicitly requires or defaults to a specific language without documenting that constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file's natural-language comments are written only in Chinese, which can indicate a language-specific constraint without offering user choice or documenting a justified locale requirement. This matches the policy category for language or locale restrictions expressed in natural language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.