Back to skill

Security audit

Douyin Topic Hotspot Collector

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Douyin hotspot search helper that reads public visible page data and only writes files when export is requested.

Install this if you are comfortable with the agent using browser/network access to view public Douyin search results and, when you request export, writing the collected results to your chosen folder or Desktop. The skill documentation and outputs are Chinese-only.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file presents all user-facing failure output entirely in Chinese, with no indication that language selection is optional or tied to a documented region-specific requirement. Under the policy, language constraints should be user-selectable or explicitly justified to avoid imposing a locale without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains user-facing natural language exclusively in Chinese, but it does not state that the skill is Chinese-only, region-specific, or that users may choose another language. Under the policy rule for language/locale violations, forcing a specific language without opt-in can be a violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

A language or locale policy issue may exist when a skill effectively forces one language without user opt-in. This README presents all user-facing documentation only in Chinese and does not indicate that another language option is available or that the language is intentionally region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file describes a behavior that can affect user data or system state: exporting results. While L31 notes that write permission is required and L37 says non-specified paths will not be modified, the description does not clearly warn users that the skill will create or modify files as part of export behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all user-facing content in Chinese and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the language/locale policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.