Back to skill

Security audit

自动将视频发布到中国三大主流平台:**B站(Bilibili)**、**抖音(Douyin)**、**小红书(Xiaohongshu)**。

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real video publisher, but it stores reusable account sessions in plaintext and can automatically post public content with under-disclosed defaults.

Review before installing. Use only accounts you control, assume commands may immediately upload and publish publicly, avoid the default generated content unless you have checked it, and do not store or share the generated cookies directory. Prefer a version that pins dependencies, removes anti-detection claims, documents all supported platforms, stores sessions securely, and requires an explicit final confirmation or dry run before posting.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
auto_publish.py:25
Finding

Authentication Cookies Stored in Predictable Plaintext Files Without Explicit Access Controls

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unbounded Playwright Dependency Permits Unreviewed Future Releases

Content
View full analysis
=1.40.0 ``` Related installation instructions also download a browser binary: ```bash pip install -r requirements.txt python -m playwright install chromium ``` The README alternatively instructs users to install the latest matching package directly: ```bash pip install playwright python -m playwright install chromium ``` ### Technical Analysis The lower-bound-only constraint accepts every future Playwright release. Consequently, installations performed at different times may execute materially different dependency code without a new review of this project. The documented Chromium installation step also downloads and installs a browser binary selected by the installed Playwright version. Playwright and its browser process receive access to local video files and authenticated browser sessions. A compromised upstream release, package-index account, package-resolution environment, or downloaded browser artifact would therefore execute in a sensitive context. This finding does not establish that the current Playwright package is malicious. It identifies a reproducibility and supply-chain control weakness caused by accepting unreviewed future package and browser versions without integrity hashes. ### Attack Path 1. A user follows the installation instructions. 2. The package resolver selects a future Playwright release because the requirement only specifies `>=1.40.0`. 3. Playwright installs or retrieves its corresponding Chromium build. 4. If the selected package or browser artifact has been compromised, malicious code executes with the installing user's privileges. 5. During Skill execution, that code may access uploaded video files, browser data, platform session cookies, and network connections available to the process. ### Impact Assessment The m ...[truncated 526 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented behavior does not fully match the detected functionality: undisclosed platform support, cookie read/save/reuse, local directory scanning, and automatic metadata generation materially expand what the skill can do. Hidden or under-described capabilities are dangerous because they prevent informed consent and can lead to unreviewed publication, credential handling, or local data processing beyond what the user expects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file instructs the user to run a publishing command that posts videos to B站、抖音、小红书, including an example that publishes to all platforms, but it does not warn that the action may upload content publicly or affect external accounts. For markdown files, safety-affecting behavior that can impact user data or account integrity should be disclosed clearly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README promotes persistent cookie storage and detailed logging but does not warn that cookies may grant full account access or that logs may capture sensitive metadata, paths, or operational details. This omission can lead users to store authentication material insecurely and expose account data if the host or repository is compromised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly advertises '反检测技术' to bypass anti-bot and anti-crawling protections, which signals intent to evade platform safeguards rather than simply automate a legitimate workflow. Even in documentation, this increases the likelihood the skill is designed to violate platform controls and can facilitate account restrictions, abuse, or policy evasion.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation encourages one-command automated publishing and button-click automation without emphasizing that posting is an externally visible, potentially irreversible action. Users may accidentally publish unintended content across multiple platforms, causing reputational, legal, or compliance harm.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill describes capabilities that imply local file access and state persistence, but it does not declare an explicit tool scope such as permissions or allowed-tools. That makes the effective access boundary unclear to users and reviewers, increasing the risk of unintended file reads/writes such as cookie storage, log creation, or scanning local video directories.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation mentions cookie persistence and detailed logging without warning users about credential and privacy risks. Persisted cookies can expose authenticated sessions, and logs may capture sensitive account, file, or publication details; in an automation skill handling multiple social-media accounts, that materially increases the chance of account compromise or privacy leakage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill's default invocation appears to immediately publish content to live third-party platforms, but the documentation does not present a prominent warning or confirmation requirement. In a publishing automation context, this is especially risky because a single command can cause irreversible external actions such as public posting, account policy violations, or accidental release of sensitive or wrong content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill description claims support for three Chinese platforms, but the code also supports Kuaishou and can publish to all platforms in bulk. This mismatch undermines user consent and transparency because the tool can act on an additional account/platform beyond what the metadata advertises.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script saves live authenticated browser cookies for creator accounts to local JSON files without encryption, permission hardening, or an explicit warning. Anyone with filesystem access can potentially reuse those cookies to hijack social media sessions and publish or manage content as the victim.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script is presented as a generic auto-publisher, but it automatically generates and publishes specific Iran war / Middle East news content. That hidden specialization increases the risk of deceptive or unauthorized content posting, especially for sensitive geopolitical topics where mistakes or misuse can cause account, reputational, or policy harm.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The main workflow performs real submission actions to one or more platforms after only a menu choice, without a final explicit confirmation summarizing the irreversible consequences. Because the tool automates authenticated posting across social accounts, a mistaken selection or bad generated content can immediately cause unintended public publication.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module docstring states the publish order is "B站 → 抖音 → 快手 → 小红书" and describes full automation for that sequence. However, the actual platform list at L57-L58 explicitly removes Kuaishou and only iterates over bilibili, douyin, and xiaohongshu, creating a direct mismatch between claimed behavior and implemented behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and all user-facing log messages are written in Chinese, and the skill description presents this as the default behavior without any opt-in or alternative locale support. Under the policy for natural-language constraints, forcing a specific language without user choice is a violation unless it is explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The startup log at L35-L36 tells the operator the tool will publish in the order "B站 → 抖音 → 小红书," while the top-level docstring at L2 claims "B站 → 抖音 → 快手 → 小红书." The code at L57-L58 confirms Kuaishou is omitted, so the file contains conflicting intent documentation about what platforms are actually handled.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The command-line description states the skill publishes only to "中国三大平台(B站、抖音、小红书)", which imposes a China-specific platform/locale scope in user-facing natural language without presenting any language or locale choice. Under the policy, locale constraints should be opt-in or explicitly justified as region-specific tooling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file content is entirely in Chinese and does not indicate that the language is optional, user-selectable, or justified as a region-specific constraint. This can constitute a natural-language locale policy issue when a skill effectively forces a specific language without opt-in or explanation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README content is entirely in Chinese, effectively forcing a specific language for operation and documentation without user opt-in or explanation. The policy allows locale constraints when clearly documented and justified, but this file does not state that the skill is intentionally limited to Chinese-speaking users or a China-specific operational context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The natural-language documentation appears entirely in Chinese, which can amount to a language/locale constraint for users who do not read Chinese. The file does not explicitly state that the skill is intended only for Chinese-speaking users or provide an opt-in language choice or alternate-language documentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The natural-language strings and descriptions throughout the file are exclusively in Chinese, with no indication that language choice is configurable or user-selected. This can violate language/locale policy when a skill implicitly forces one language rather than offering opt-in or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The dependency is specified with a lower-bound only (playwright>=1.40.0), which allows future unreviewed major or minor versions to be installed. This can introduce supply-chain risk, unexpected breaking changes, or newly introduced vulnerable transitive dependencies into an automation skill that interacts with external web platforms.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
playwright>=1.40.0

Static analysis

No suspicious patterns detected.