Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The parser extracts the first URL from arbitrary input and fetches it without restricting the domain to Douyin-owned hosts. This can be abused as an SSRF-like outbound request primitive, causing the agent to contact attacker-chosen URLs, follow redirects, and potentially interact with internal or sensitive network locations depending on where the skill runs.
