Back to skill

Security audit

Douyin Video Publisher

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent Douyin publishing purpose, but it needs Review because it enables public account posting through unpinned external MCP code and persists login cookies without enough safety guidance.

Review before installing. Pin and verify the MCP server package, run it with the least local access practical, confirm the target account and all publishing details before each post, and protect or delete saved Douyin cookies when they are no longer needed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:54
Finding

Unpinned Third-Party Package Execution via uvx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 54 and 63
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable code snippets:

text
- 命令:`uvx douyin-mcp-server`
bash
mcporter config add douyin-extract "uvx douyin-mcp-server"

Technical Analysis

The Skill instructs users to resolve and execute the third-party douyin-mcp-server package through uvx without specifying an exact version, lockfile, package hash, or other integrity control. The project also provides no bundled implementation or canonical source reference that would allow the executed package to be matched to reviewed code.

Because dependency resolution occurs when the command is invoked, the effective code can change independently of this Skill. A compromised package account, malicious release, package-name takeover, or dependency confusion event could therefore cause attacker-controlled code to execute with the privileges of the user running the MCP server.

Attack Path

  1. An attacker compromises, replaces, or publishes a malicious release under the package identity resolved as douyin-mcp-server.
  2. A user follows the documented configuration and registers uvx douyin-mcp-server as the douyin-extract MCP command.
  3. The MCP integration invokes that command during Skill use.
  4. uvx resolves and executes the mutable third-party package.
  5. Malicious package code runs with the Agent user's privileges and can access resources available to that account.

Impact Assessment

Successful exploitation provides arbitrary code execution within the security context of the user running the MCP service. Depending on that user's permissions, an attacker could read or modify local files, inspect browser-related data, access the persisted Douyin authentication cookie documented at ~/douyin-mcp-server/mcp-server/douyin-cookies.json, impersonate the authenticated account, o ...[truncated 144 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin douyin-mcp-server to a specific, audited version rather than resolving an unconstrained current release.
  • Use a locked dependency manifest with cryptographic hashes and require integrity verification before execution.
  • Document the canonical package repository, publisher identity, and expected package checksum.
  • Review the package and its transitive dependencies before deployment, and repeat the review before version upgrades.
  • Install dependencies during a controlled provisioning step instead of dynamically resolving mutable packages during routine Skill execution.
  • Run the MCP server in an isolated, least-privilege environment with narrowly scoped filesystem and network access.
  • Store Douyin cookies with owner-only permissions, prevent cookie values from entering logs, and keep them outside directories accessible to the dependency unless access is operationally required.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill promotes automatic publishing to Douyin but does not clearly warn that using it triggers external network activity and may publicly post content to a real account. This weakens informed consent and increases the risk of accidental public disclosure, unauthorized posting, or misuse when invoked by a user who does not realize the action is externally visible and account-affecting.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill instructs users to run an MCP server via uvx douyin-mcp-server without pinning a specific version or immutable source. This creates a supply-chain risk: future upstream changes or a compromised package release could alter behavior and gain access to browser sessions, cookies, uploaded media, or account actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

Referencing uvx douyin-mcp-server again in configuration instructions repeats the same unpinned dependency risk and makes unsafe installation the default path. Because this skill automates login and publishing to a real account, a malicious or altered package could directly perform unauthorized actions or steal authentication artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documents persistent local storage of Douyin login cookies without warning about the sensitivity of stored session material. If those cookies are readable by other local users, copied from backups, or mishandled by the MCP server, an attacker could reuse the session to access or post from the account without reauthentication.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.