Back to skill

Security audit

Douyin Orchestrator

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Douyin video transcription workflow with expected network access and local output files.

Install if you are comfortable with the agent fetching Douyin content, using the OpenClaw browser profile, and writing transcripts or optional video files locally. Choose dedicated output folders, review index updates before relying on them, and avoid using a logged-in browser profile for sensitive accounts unless that access is intentional.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs the agent to save transcripts and videos to local paths and to update multiple index files, but it does not require explicit user confirmation before modifying the filesystem. In an agent setting, silent writes and metadata/index changes can overwrite files, pollute knowledge stores, or persist untrusted content beyond the user's immediate intent.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The workflow directs the agent to retrieve and download Douyin video content from the network and potentially store it locally, but it does not clearly warn about external network access, content retrieval, or storage side effects. This is risky because agent users may expect analysis only, while the skill performs persistent network and download actions that can consume bandwidth, store copyrighted or sensitive material, and trigger unintended outbound requests.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.