Back to skill

Security audit

Xiangshan Douyin

Security checks for vulnerabilities and agentic risk

Overview

This Douyin API skill is coherent, but it needs Review because it tells agents to run raw curl commands with user-supplied values and an API key, creating avoidable command-injection and credential-exposure risk.

Install only if you trust api.xsdata.top and are comfortable sending Douyin links, IDs, search terms, and your XS_API_KEY to that service. Prefer setting the key in a secure environment variable, avoid pasting secrets into chat, and do not run the shown curl templates with untrusted input unless values are safely encoded/serialized and redirects are controlled.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
reference/search-user.md:20
Finding

Shell Command Injection Through Unescaped User-Controlled Parameters

Content
View full analysis
&page=&userType=' \ --header 'x-api-key: ' \ --header 'Content-Type: application/json' ``` POST request example from `reference/user-data.md:20-27`: ```bash curl -s --location 'https://api.xsdata.top/api/v1/goa/douyin/fetch-user-data' \ --header 'x-api-key: ' \ --header 'Content-Type: application/json' \ --data '{ "sec_user_id": "", "share_text": "" }' ``` The same unsafe construction pattern appears in the other listed reference files. ### Technical Analysis The Skill directs the agent to parse values from `$ARGUMENTS` or interactive user input and substitute them directly into shell command templates. Parameters such as `keyword`, `share_text`, `sec_user_id`, `aweme_id`, pagination cursors, and filtering values are placed inside single-quoted shell strings without shell-safe escaping. A single quote supplied inside one of these parameters can terminate the intended quoted string. Subsequent shell metacharacters can then introduce additional commands. This affects both: - Query parameters embedded in a single-quoted URL. - Values embedded in a single-quoted JSON request body. The documentation does not require strict validation, structured argument passing, URL encoding, or JSON serialization before invoking `curl`. Consequently, an agent that follows these templates through a shell may interpret attacker-controlled input as shell syntax instead of data. ...[truncated 1618 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:78
Finding

API Key May Be Disclosed When Following Cross-Origin Redirects

Content
View full analysis
' \ --header 'x-api-key: ' \ --header 'Content-Type: application/json' \ --data '' ``` ```bash curl -s --location 'https://api.xsdata.top?' \ --header 'x-api-key: ' \ --header 'Content-Type: application/json' ``` Equivalent use of `--location` together with the sensitive `x-api-key` header appears in every API-specific reference file listed above. ### Technical Analysis The request templates combine: - `--location`, which instructs `curl` to follow HTTP redirects. - A manually supplied `x-api-key` header containing a sensitive credential. Custom headers supplied with `--header` can be included in redirected requests. If the API endpoint returns a redirect to a different origin, the credential may consequently be transmitted to a host that was not intended to receive it. This can occur if the API service is compromised, an endpoint is misconfigured, or an upstream component allows an attacker to influence redirect responses. HTTPS protects the request while it is in transit, but it does not prevent disclosure to the destination selected by a redirect. Sending the key to the declared API host is necessary for the Skill's functionality. Permitting the same credential to follow an unrestricted redirect to another origin is not necessary and exceeds minimum-privilege network behavior. ### Attack Path 1. The agent invokes one of the documented `curl --location` commands and attaches the use ...[truncated 944 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (24)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description and main instructions are written entirely in Chinese and present the skill as operating in Chinese without any note that users may choose another language. Under the policy, a language or locale constraint should be optional, justified, or explicitly offered as a user choice.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill instructs the agent to send user-supplied data and an API credential to an external third-party service, which creates a real data exfiltration and privacy risk. Because the skill processes arbitrary user-provided Douyin links, IDs, and search terms, sensitive or regulated data could be transmitted off-platform without sufficient minimization, consent, or trust validation of the remote endpoint.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

POST 接口:

bash
curl -s --location 'https://api.xsdata.top<endpoint>' \
--header 'x-api-key: <api_key>' \
--header 'Content-Type: application/json' \
--data '<json_body>'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill sends user-provided search terms and an API key to a third-party endpoint, but it does not clearly warn the user that their input will be transmitted externally or obtain consent before doing so. In an agent setting, this can expose potentially sensitive search intent and credentials to an outside service, especially because the workflow explicitly asks for the API key interactively if it is not already in the environment.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This skill intentionally performs an external network request to a non-local service, which is expected for an API integration, but it still creates a real data-exposure boundary. The danger is increased by combining outbound transmission with user search content and an authentication header, without any safety language about third-party handling, consent, or secret-management constraints.

Content

Scanner excerpt · reference/search-user.md (reported line 20)May include surrounding context.

  1. 使用 curl 调用接口(注意:这是 GET 请求):
bash
curl -s --location 'https://api.xsdata.top/api/v1/douyin/search-user?keyword=<keyword>&page=<page>&userType=<userType>' \
--header 'x-api-key: <api_key>' \
--header 'Content-Type: application/json'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly sends a user-provided search keyword and an API key to an external third-party endpoint, but the skill metadata/description does not warn that user input will leave the local environment. This creates a privacy and transparency issue: users may unknowingly disclose sensitive search terms, and the API credential is also exposed to outbound use against a remote service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This skill performs a direct external HTTP request to a third-party domain, transmitting user-controlled query data and authentication material. In context, external transmission is expected for an API integration, but it still presents data exposure and trust-boundary risk because the destination is outside the agent environment and no warning or consent flow is described.

Content

Scanner excerpt · reference/search-video.md (reported line 37)May include surrounding context.

  1. 使用 curl 调用接口(注意:这是 GET 请求):
bash
curl -s --location 'https://api.xsdata.top/api/v1/douyin/search-video?keyword=<keyword>&page=<page>&searchId=<searchId>&sortType=<sortType>&publishTime=<publishTime>&duration=<duration>' \
--header 'x-api-key: <api_key>' \
--header 'Content-Type: application/json'

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The skill directs the agent to perform a curl request to an external domain and include user-supplied identifiers in the request body along with an API key in headers. External transmission is expected for an API integration, but without explicit consent/notification and data-handling safeguards, it creates a real privacy and secret-handling risk.

Content

Scanner excerpt · reference/user-data.md (reported line 17)May include surrounding context.

  1. 从 $ARGUMENTS 中解析参数。如果参数不完整,向用户询问缺失的必填参数。
  2. 读取 API Key:优先从环境变量 XS_API_KEY 获取,如果未设置则向用户询问。
  3. 使用 curl 调用接口:
bash
curl -s --location 'https://api.xsdata.top/api/v1/goa/douyin/fetch-user-data' \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly sends user-provided Douyin identifiers and profile-share text to a third-party API endpoint, but it does not instruct the agent to warn the user that their input will be transmitted off-platform. These identifiers and share links can be personal or account-linked data, so silent transmission creates a privacy and consent risk even if the API is legitimately used for the skill's function.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The hardcoded external endpoint confirms that the skill transmits data to a third-party service outside the local agent environment. In this context the transmission is functionally necessary, but it is still security-relevant because the skill lacks disclosure, consent language, or trust/privacy constraints around the remote service.

Content

Scanner excerpt · reference/user-data.md (reported line 20)May include surrounding context.

  1. 使用 curl 调用接口:
bash
curl -s --location 'https://api.xsdata.top/api/v1/goa/douyin/fetch-user-data' \
--header 'x-api-key: <api_key>' \
--header 'Content-Type: application/json' \
--data '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs the agent to retrieve an API key from the environment or directly from the user, then transmit it to a third-party service, but it does not explicitly warn the user that both the credential and supplied identifiers will be sent off-platform. This creates a real privacy and secret-handling risk because users may disclose sensitive API credentials or personal data without clear informed consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The skill explicitly sends user-supplied data and an API key to an external domain using curl. External transmission is expected for an API integration, but it is still a genuine security concern because sensitive inputs, account identifiers, and credentials leave the agent boundary and are disclosed to a third party.

Content

Scanner excerpt · reference/user-video-list.md (reported line 20)May include surrounding context.

  1. 从 $ARGUMENTS 中解析参数。如果参数不完整,向用户询问缺失的必填参数。
  2. 读取 API Key:优先从环境变量 XS_API_KEY 获取,如果未设置则向用户询问。
  3. 使用 curl 调用接口:
bash
curl -s --location 'https://api.xsdata.top/api/v1/goa/douyin/fetch-user-video-list' \

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The hardcoded external endpoint confirms that requests are sent to a third-party service outside the local environment. In this skill context that behavior is functional rather than overtly malicious, but it still presents data exposure and trust-boundary risks, especially since the skill handles API credentials and user-related Douyin identifiers.

Content

Scanner excerpt · reference/user-video-list.md (reported line 23)May include surrounding context.

  1. 使用 curl 调用接口:
bash
curl -s --location 'https://api.xsdata.top/api/v1/goa/douyin/fetch-user-video-list' \
--header 'x-api-key: <api_key>' \
--header 'Content-Type: application/json' \
--data '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs the agent to obtain an API key from either an environment variable or direct user input, then transmit it to a third-party endpoint in a request header. While this is a common integration pattern, it becomes a security issue here because there is no user-facing warning about credential handling, no minimization guidance, and no indication of secure secret-entry practices, increasing the risk of accidental credential exposure or inappropriate collection.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The skill directs external transmission of user-supplied data and a credential to api.xsdata.top via curl. External transmission is expected for an API connector, but it is still security-relevant because sensitive inputs, including the API key and potentially identifying share text, are sent off-platform without an explicit consent or disclosure step.

Content

Scanner excerpt · reference/video-comment.md (reported line 19)May include surrounding context.

  1. 从 $ARGUMENTS 中解析参数。如果参数不完整,向用户询问缺失的必填参数。
  2. 读取 API Key:优先从环境变量 XS_API_KEY 获取,如果未设置则向用户询问。
  3. 使用 curl 调用接口:
bash
curl -s --location 'https://api.xsdata.top/api/v1/goa/douyin/fetch-video-comment' \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · reference/video-comment.md (reported line 22)May include surrounding context.

  1. 使用 curl 调用接口:
bash
curl -s --location 'https://api.xsdata.top/api/v1/goa/douyin/fetch-video-comment' \
--header 'x-api-key: <api_key>' \
--header 'Content-Type: application/json' \
--data '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly sends user-supplied Douyin identifiers or share text, along with an API key, to a third-party endpoint. While this is expected for the tool’s functionality, the skill description does not clearly disclose the external transmission or the privacy implications, so users may provide links or share text without informed consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The documented workflow instructs the agent to perform a network request to an external service using curl and to include both user-provided content and a credential header. This is not inherently malicious, but it is a real data egress path and can expose user data and credentials to a third party if the operator or user is unaware.

Content

Scanner excerpt · reference/video-detail.md (reported line 17)May include surrounding context.

  1. 从 $ARGUMENTS 中解析参数。如果参数不完整,向用户询问缺失的必填参数。
  2. 读取 API Key:优先从环境变量 XS_API_KEY 获取,如果未设置则向用户询问。
  3. 使用 curl 调用接口:
bash
curl -s --location 'https://api.xsdata.top/api/v1/goa/douyin/fetch-video-detail' \

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The hardcoded external endpoint confirms that the skill depends on a third-party service outside the local trust boundary. In context this matches the tool’s intended purpose, but it still creates a genuine privacy and supply-chain risk because queries, share text, and authentication material are sent off-platform.

Content

Scanner excerpt · reference/video-detail.md (reported line 20)May include surrounding context.

  1. 使用 curl 调用接口:
bash
curl -s --location 'https://api.xsdata.top/api/v1/goa/douyin/fetch-video-detail' \
--header 'x-api-key: <api_key>' \
--header 'Content-Type: application/json' \
--data '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to transmit user-supplied Douyin identifiers or share text together with an API key to a third-party endpoint, but it does not require an explicit user-facing notice or consent before sending the data. This creates a real privacy and secret-handling risk because share text may contain personal or tracking information, and prompting for an API key in chat can expose credentials to the agent or logs.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The documented workflow explicitly sends user-controlled input and an authentication secret to an external service. In this skill's context, external transmission is expected for API functionality, but it is still security-relevant because the skill lacks guardrails around consent, minimization, and secure handling of the API key.

Content

Scanner excerpt · reference/video-statistics.md (reported line 26)May include surrounding context.

  1. 从 $ARGUMENTS 中解析参数。如果参数不完整,向用户询问缺失的必填参数。
  2. 读取 API Key:优先从环境变量 XS_API_KEY 获取,如果未设置则向用户询问。
  3. 使用 curl 调用接口:
bash
curl -s --location 'https://api.xsdata.top/api/v1/goa/douyin/fetch-video-statistics' \

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The hardcoded third-party endpoint confirms that data leaves the local agent boundary and goes to api.xsdata.top. That is not inherently malicious in an API integration skill, but it becomes a genuine security concern when paired with user-provided content and API-key transmission without clear disclosure and handling requirements.

Content

Scanner excerpt · reference/video-statistics.md (reported line 29)May include surrounding context.

  1. 使用 curl 调用接口:
bash
curl -s --location 'https://api.xsdata.top/api/v1/goa/douyin/fetch-video-statistics' \
--header 'x-api-key: <api_key>' \
--header 'Content-Type: application/json' \
--data '{

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

All user-facing instructions in the file are presented in Chinese, with no indication that the user can choose another language or that the language restriction is intentional and documented. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file's natural-language instructions are entirely in Chinese and do not indicate that the user can choose another language or that the skill is intentionally limited to Chinese-speaking users. Under the language/locale policy, forcing a specific language without opt-in can be a policy violation unless clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

All user-facing instructions and labels in the file are presented exclusively in Chinese. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale limitation is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.