Back to skill

Security audit

Douyin Script Writer

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly aligned with Douyin script writing, but it automatically saves user-provided prompt details to a predictable local file without clear opt-in.

Review this skill before installing if you may enter confidential campaign plans, unreleased product details, or private audience targeting. Prefer a version that makes saving prompts opt-in, writes only to a user-selected private path, and documents that the output is Chinese/Douyin-oriented.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate-script.sh:154
Finding

Predictable Plaintext Prompt Storage with Symlink-Following File Write

Content
View full analysis

Vulnerability Details

File Location: scripts/generate-script.sh, lines 154-157
Vulnerability Type: Predictable plaintext storage and unsafe file write
Risk Level: Medium

Vulnerable Code

bash
# Also save the prompt to a file for reference
PROMPT_FILE="${SKILL_DIR}/references/last-prompt.txt"
mkdir -p "$(dirname "$PROMPT_FILE")"
BUILD_PROMPT > "$PROMPT_FILE"

The stored prompt is assembled from user-controlled CLI parameters parsed at lines 52-58 and interpolated by BUILD_PROMPT at lines 88-102:

bash
--topic)  TOPIC="$2";   shift 2 ;;
--duration) DURATION="$2"; shift 2 ;;
--style)  STYLE="$2";   shift 2 ;;
--audience) AUDIENCE="$2"; shift 2 ;;
--product) PRODUCT="$2"; shift 2 ;;
--points) SELLING_POINTS="$2"; shift 2 ;;
--cta)    CTA="$2";     shift 2 ;;
bash
BUILD_PROMPT() {
    echo "请生成一个抖音短视频脚本,主题:${TOPIC}"
    echo "时长:${DURATION}秒"
    echo "风格:${STYLE}"
    echo "目标受众:${AUDIENCE}"
    if [[ -n "$PRODUCT" ]]; then
        echo "产品:${PRODUCT}"
    fi
    if [[ -n "$SELLING_POINTS" ]]; then
        echo "卖点:${SELLING_POINTS}"
    fi
    if [[ -n "$CTA" ]]; then
        echo "行动号召(CTA):${CTA}"
    fi

Technical Analysis

Every non-JSON invocation automatically writes the generated prompt to the fixed package-relative path references/last-prompt.txt. The persisted data can include topics, target audiences, unpublished product information, selling points, and campaign calls to action.

This persistence is not required to print or generate the prompt and is performed without explicit user consent. The implementation does not establish restrictive file permissions, create the file atomically, prevent concurrent overwrites, or verify that the destination is a regular file rather than a symbolic link.

Standard shell redirection follows symbolic links. Therefore, an attacker who can modify the package directory or the existing destination can replace references/last-prompt.txt with a symbolic link. A later invo ...[truncated 1591 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not persist generated prompts by default. Print the prompt to standard output and require an explicit option such as --output PATH before writing it.
  • Clearly disclose that the output may contain sensitive user-supplied information and obtain explicit user intent before storing it.
  • If automatic caching is essential, place files in a user-private directory created with mode 0700, and create files with mode 0600.
  • Reject symbolic-link destinations. Open a newly created file with exclusive-creation and no-follow semantics through a suitable helper rather than ordinary shell redirection.
  • Use a unique per-invocation filename and atomic creation to avoid cross-user leakage and concurrent overwrite races.
  • Verify that any user-selected destination is an expected regular file and that its parent directory is trusted.
  • Define a retention policy and securely remove cached prompts when they are no longer needed.
  • Avoid executing the skill with elevated privileges when its installation directory or output location is writable by less-trusted users.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description says the skill turns a topic into a Douyin-ready short video script with hook, storyboard, captions, and BGM suggestions. However, this code chunk does not generate such a script. Its core function is to assemble and output a prompt for another AI assistant to use later, plus optionally serialize that prompt as JSON. The script explicitly tells the user to paste the prompt into an AI assistant to generate the full script. That is a materially different primary behavior from directly producing the requested script. Additionally, it saves the generated prompt to a local file, which is a real side effect not mentioned in the declaration. The extra inclusion of recommended posting time and cover text is a minor scope difference, but the main mismatch is that the code is a prompt-builder wrapper rather than a script generator.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose describes a generative skill that produces Douyin-ready short video scripts from a topic. The supplied code does not generate scripts, hooks, storyboards, captions, or BGM suggestions. Instead, it validates an already-produced JSON object against required fields and structural rules, then prints success or error messages. While the schema being validated is related to Douyin script output, the primary purpose is materially different: validation rather than generation. Therefore, the description does not accurately represent the code's actual behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The markdown includes extensive example prompts, outputs, and usage guidance in Chinese, but it does not state that the skill is China/Chinese-only or offer an explicit language preference option. This can amount to a language/locale policy issue because the skill appears to assume a specific output language by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON template is written entirely in Chinese, including section names and descriptions, which effectively constrains outputs to a specific language/locale. The file does not offer a language choice or document that the template is intentionally region-specific, so it may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The schema title and examples indicate a Douyin-focused script-writing skill, and multiple enum/example values are exclusively in Chinese. Because the file does not provide any user opt-in, language-selection field, or explicit justification that the skill is intentionally region/language-specific, it appears to enforce a specific language/locale by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated prompt explicitly instructs the assistant in Chinese and the defaults/style taxonomy are also Chinese-specific, which effectively forces a specific language/locale. Under the policy, locale-specific behavior should either be optional for the user or clearly documented as a justified regional constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script persists user-supplied topic, product, selling points, and CTA content to a predictable local file without warning the user beforehand. If users provide confidential campaign plans, unreleased product details, or sensitive business data, that information can remain on disk and be exposed to other local users, backups, or later tooling that reads the workspace.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON contains user-facing genre, description, and recommendation strings entirely in Chinese, which can amount to forcing a specific language without opt-in. The policy allows locale constraints when explicitly documented and justified, but this file provides no such justification or alternative language handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file is entirely written as a directive in Chinese and instructs the model to generate a specific Chinese-language Douyin script, with no indication that the user can choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON template contains user-facing natural-language content entirely in Chinese, including the template name and section descriptions. Because the file provides no opt-in, fallback, or justification for a Chinese-only locale, it may violate the policy against forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSON template includes multiple user-facing section names and descriptions in Chinese, while the template title is in English. Because the file provides no opt-in, language selection, or justification that it is intended only for Chinese-speaking users, it may violate a language/locale policy requiring user choice or documented locale constraints.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a skill that turns a topic into a Douyin-ready script, which implies content generation/output but not persistent local storage. This script additionally creates a references directory and saves the generated prompt to last-prompt.txt as a side effect.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.