Back to skill

Security audit

social-parser

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Douyin/Xiaohongshu link parser that uses an external CLI and remote API, with no evidence of hidden persistence, credential access, or destructive behavior.

Use this only for Douyin or Xiaohongshu links you intend to send to a parser. Verify the gnomic-cli npm package before installing it globally, and avoid submitting private, restricted, or sensitive links unless you are comfortable with remote API processing.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill description includes broad trigger phrases such as '分析这个视频' and general parsing/extraction language, which can match many ordinary user requests beyond the intended Douyin/Xiaohongshu link-parsing scope. This can cause accidental invocation of a networked skill that fetches third-party content, increasing the chance of unintended external requests, privacy issues, or incorrect tool routing.

Static analysis

No suspicious patterns detected.