Back to skill

Security audit

Douyin Creator Cn

Security checks for vulnerabilities and agentic risk

Overview

This Douyin creator skill only runs local preset Bash helpers and shows no hidden data access or persistence, though its analysis is mostly static advice.

Install only if you want Chinese-language, Douyin-specific static guidance. Do not treat the competitor metrics or timing advice as real analytics, because the scripts do not fetch live platform data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description promises a multi-function Douyin creator assistant covering tag recommendations, best posting times, title optimization, and competitor analysis. The supplied code only prints a hardcoded mock competitor-analysis template for a provided account name. While competitor analysis is partially aligned in theme, the implementation is materially narrower and mostly simulated, with no API access or real analysis. Key declared capabilities such as title optimization and genuine tag recommendations are absent, so the description overstates what the code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The code only implements one subset of the declared description: tag recommendations. It does not contain any logic for recommending posting times, optimizing titles, or analyzing competitors. There are no external API calls, data access, or analysis components that would support those additional declared features. While the implemented behavior is aligned with part of the description, the overall declared purpose overstates the skill's capabilities, so this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The supplied code chunk is narrowly focused on title optimization: it checks title length, presence of numbers/punctuation/pronouns/suspense words, and generates suggested alternative titles. This behavior fits one part of the declared description ('title optimization') but does not implement the other advertised capabilities: tag recommendations, best posting times, or competitor analysis. There is no evidence of unrelated or risky undeclared behavior, but the declared description materially overstates the skill's capabilities compared with this code chunk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The package description is entirely in Chinese and presents the skill as a China-specific creator assistant, but the manifest does not indicate that language or locale is optional, user-selectable, or otherwise justified as a documented regional-only tool. This creates a natural-language locale constraint that may exclude users or violate language-choice expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This shell script presents its usage, analysis, and recommendations only in Chinese, which imposes a specific language on users without opt-in. The policy explicitly calls for flagging language or locale constraints unless the skill offers a choice or clearly documents a justified regional scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill description and examples are written as a bilingual README, but all concrete invocation examples and content categories are tailored specifically to Douyin and Chinese-language inputs. Under the policy, forcing a specific language or locale without user opt-in can be a natural-language policy issue, and the README does not explicitly offer alternate language/locale modes or make the locale restriction a user-selected option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The file presents the skill as specifically for Douyin/TikTok China, which is a locale-specific context. Under the policy rule, locale constraints should either be optional for the user or clearly documented as justified; this description does not explicitly provide either.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file describes a competitor-analysis feature but provides no user-facing warning about potential privacy, platform-policy, or data-handling implications of analyzing other accounts. For markdown files, omissions of warnings about behaviors that could affect user data or privacy should be flagged.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script uses Chinese-language comments and user-facing output exclusively, including the usage instructions. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is clearly justified, which is not documented here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This shell script's natural-language comments, usage text, and output are entirely in Chinese, and there is no indication that the skill is intentionally region-specific or that users can opt into another language. Under the language/locale policy, forcing a specific language without opt-in is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script's comments, usage text, and all user-facing output are exclusively in Chinese, which imposes a fixed language on users. The file does not provide any opt-in, fallback, or explanation that the skill is intentionally region-specific, so this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.