Back to skill

Security audit

抖音文案提取

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent Douyin-to-Word purpose, but its documented workflow can put untrusted Douyin text into a shell command without safe argument handling.

Review before installing. Use this only if you expect the agent to access Douyin links and create/send DOCX files, and avoid letting the agent build shell commands by pasting scraped titles, author names, or full post text directly into quoted command arguments. A safer version should pass values through a non-shell argument array, stdin, or a temporary file.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:34
Finding

Shell Command Injection Through Untrusted Douyin Content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:34
Vulnerability Type: Shell command injection through unsafe interpolation of remote content
Risk Level: High

Vulnerable Code:

bash
python3 scripts/create_docx.py --title "标题" --author "作者" --content "完整文案" --output /tmp/output.docx

Technical Analysis

The documented workflow instructs the agent to place the title, author nickname, and full post content extracted from a remote Douyin page directly into a shell command. These values are controlled by the publisher of the referenced Douyin post and must therefore be treated as untrusted input.

Enclosing substituted content in double quotes is not sufficient when an agent constructs the final command as shell source text. Shell command substitutions such as $(command) and backtick expressions remain active inside double-quoted shell syntax. Embedded quotation marks can also terminate the intended argument and introduce additional shell operators.

For example, if remotely extracted content is inserted into the command as:

text
$(attacker-controlled-command)

the generated command may become:

bash
python3 scripts/create_docx.py --title "标题" --author "作者" --content "$(attacker-controlled-command)" --output /tmp/output.docx

The shell evaluates the command substitution before invoking Python. The vulnerability is in the skill's command-construction instructions rather than in scripts/create_docx.py, which processes arguments without independently invoking a shell.

Attack Path

  1. An attacker publishes a Douyin post whose description, title, or author-controlled metadata contains shell command-substitution syntax or characters that break out of the intended quoting context.
  2. The attacker persuades a victim to submit that Douyin link to an agent using this skill, or the victim independently requests extraction of the malicious post.
  3. Foll ...[truncated 1111 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not construct shell source code by interpolating extracted titles, author names, or post content.

  2. Invoke the script through a process API that accepts an argument array and disables shell processing. For example:

    python
    subprocess.run(
        [
            "python3",
            "scripts/create_docx.py",
            "--title",
            title,
            "--author",
            author,
            "--content",
            content,
            "--output",
            output_path,
        ],
        shell=False,
        check=True,
    )
    
  3. Prefer passing potentially large post content through standard input or a securely created temporary file rather than as a command-line argument. This also avoids command-line length limits and exposure through process listings.

  4. If a shell-based interface cannot be eliminated, apply a proven per-argument escaping mechanism such as shlex.quote to every untrusted value. Manual quote replacement or filtering selected metacharacters is insufficient.

  5. Generate output paths internally rather than deriving them directly from author-controlled names. If author names are included in filenames, normalize them to a strict allowlist and ensure the resolved path remains within the designated output directory.

  6. Execute the extraction workflow with least privilege, restricted filesystem access, and constrained outbound networking to reduce the impact of any future command-execution flaw.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims it will fetch and extract full Douyin content from a link, but the described implementation is incomplete or inconsistent with that promise. This mismatch can mislead users and downstream agents about what external access and data handling actually occur, increasing the risk of unsafe automation decisions or accidental misuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger conditions include broad phrases like extracting content or making a file, which could cause the skill to activate during ordinary conversation without clear user intent. Unintended activation is risky here because the skill may perform network access and generate/send files automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The workflow performs external web requests and creates a document, yet the skill text does not clearly warn the user that it will fetch third-party content and send a generated file. Lack of transparency can expose users to privacy, compliance, or consent issues, especially when content is copied verbatim from an external platform.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and argument/help strings specify Chinese-language behavior and wording throughout, such as generating a Word file from Douyin copy and using Chinese field labels. This creates a locale-specific constraint in natural language without any user opt-in or explanation that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

文件中的自然语言说明全部以中文撰写,并围绕中文平台与中文输出规则展开,但未说明是否支持其他语言或允许用户选择输出语言。按规则,若技能强制特定语言而无用户 opt-in,属于自然语言政策问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.