Back to skill

Security audit

抖音视频智能助手

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real Douyin/video transcription helper, but it needs Review because it handles secrets unsafely and its command execution path can be abused with crafted URLs or filenames.

Install only after reviewing the command-injection and API-key handling risks. Do not paste API keys into chat; configure secrets out of band and rotate any key already shared. Treat links and filenames as untrusted, and avoid running this skill on crafted input until command execution is changed to non-shell argument arrays with strict URL validation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/transcribe.js:104
Finding

Arbitrary Command Execution Through Shell Command Injection

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:257
Finding

API Secret Requested Through Conversational Input

Content
View full analysis
A free Groq API key is required for speech recognition. > > 1. Open https://console.groq.com > 2. Sign in with Google or GitHub > 3. Select API Keys, then Create API Key > 4. Copy the key, which begins with `gsk_`, and send it to me After receiving the key, update `.env`. ``` ### Technical Analysis The Skill explicitly directs the user to transmit a Groq API key through the Agent conversation. API keys are authentication secrets and should not be entered into conversational channels. A key sent through chat may be retained in: - Conversation history. - Agent execution traces. - Model-provider logs or telemetry. - Debug output and monitoring systems. - Session context supplied to later tools or model calls. - Backups of the Agent workspace or message store. The instruction then directs the Agent to write the received key into a plaintext `.env` file. Although environment files are a common local configuration mechanism, the project does not instruct the Agent to apply restrictive file permissions or verify that the file is excluded from source control and backups. This finding does not demonstrate intentional credential exfiltration. The risk arises from collecting a sensitive credential through an unnecessarily exposed channel. ### Attack Path 1. The Skill detects that `GROQ_API_KEY` is absent. 2. It asks the user to create an API key and send the complete key through chat. 3. The user pastes the secret into the conversation. 4. The key becomes part of the Agent session and may be stored in chat history, logs, traces, or telemetry. 5. The Agent writes the key into `.env`. 6. Anyone with access to the retained conversation, d ...[truncated 694 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (28)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 57)May include surrounding context.

bash
cd ~/.openclaw/workspace/skills/douyin-transcribe
cp .env.example .env
# 编辑 .env,填入 GROQ_API_KEY

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The manifest presents the skill as a simple transcription assistant, but the instructions include remote media extraction, file persistence, browser scripting, shell execution, and external API submission of content. This mismatch prevents informed consent and can cause users to expose private video/audio data or local environment state without realizing the full behavior.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

md
node scripts/transcribe.js "<原始链接>"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
node scripts/transcribe.js "<原始链接>"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
node scripts/transcribe.js "<原始链接>"

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Instructing the agent to read the skill's .env file exposes a credential-bearing file to the model and toolchain even though only the presence of configuration is needed. Reading .env content can reveal API keys or other secrets and is broader than necessary for normal transcription behavior.

Content

Scanner excerpt · SKILL.md (reported line 247)May include surrounding context.

当用户第一次触发时,按以下顺序检查环境。缺什么补什么。

检查 1:.env 文件

text
read: <skill目录>/.env

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

Automatically copying or managing a .env file is not inherently malicious, but in the context of this skill it is part of a credential-handling workflow performed by the agent. That increases the chance of misconfiguration or later exposure of secrets if the agent also reads or writes values in that file.

Content

Scanner excerpt · SKILL.md (reported line 250)May include surrounding context.

检查 1:.env 文件

text
read: <skill目录>/.env

不存在则从 .env.example 复制。

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly asks users to send a Groq API key in chat without any warning that the value is a sensitive credential. Secrets pasted into chat may be stored in logs, appear in model context, or be exposed to other tools, creating a significant credential-compromise risk.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill directs the agent to solicit a raw API key from the user and persist it into local configuration. This is dangerous because it combines secret collection, local storage, and agent-mediated handling, increasing the attack surface for leakage, misuse, and later exfiltration.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 307)May include surrounding context.

md
const path = require('path');
const https = require('https');

// 加载 .env 文件
function loadEnvFile() {
  const envPath = path.join(__dirname, '..', '.env');
  if (fs.existsSync(envPath)) {

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/transcribe.js (reported line 12)May include surrounding context.

js
const path = require('path');
const https = require('https');

// 加载 .env 文件
function loadEnvFile() {
  const envPath = path.join(__dirname, '..', '.env');
  if (fs.existsSync(envPath)) {

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/transcribe.js (reported line 135)May include surrounding context.

js
const path = require('path');
const https = require('https');

// 加载 .env 文件
function loadEnvFile() {
  const envPath = path.join(__dirname, '..', '.env');
  if (fs.existsSync(envPath)) {

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/transcribe.js (reported line 140)May include surrounding context.

js
const path = require('path');
const https = require('https');

// 加载 .env 文件
function loadEnvFile() {
  const envPath = path.join(__dirname, '..', '.env');
  if (fs.existsSync(envPath)) {

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/transcribe.js (reported line 14)May include surrounding context.

js
// 加载 .env 文件
function loadEnvFile() {
  const envPath = path.join(__dirname, '..', '.env');
  if (fs.existsSync(envPath)) {
    const envContent = fs.readFileSync(envPath, 'utf-8');
    envContent.split('\n').forEach(line => {

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 45)May include surrounding context.

md
**Windows:** 从 [gyan.dev](https://www.gyan.dev/ffmpeg/builds/) 下载 release full 版本,解压后将 `bin` 目录加入 PATH。

**Linux:** `sudo apt install ffmpeg`

### 2. 获取 Groq API Key(免费)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 51)May include surrounding context.

md
1. 打开 [console.groq.com](https://console.groq.com)
2. Google 或 GitHub 登录(不需要信用卡)
3. **API Keys** → **Create API Key** → 复制(`gsk_` 开头)

### 3. 配置

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 51)May include surrounding context.

md
1. 打开 [console.groq.com](https://console.groq.com)
2. Google 或 GitHub 登录(不需要信用卡)
3. **API Keys** → **Create API Key** → 复制(`gsk_` 开头)

### 3. 配置

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explains that audio is processed by Groq, but it does not present this as a clear user-facing privacy warning before use or installation. Because the skill handles user-supplied video/audio that may contain personal or sensitive content, sending transcripts or audio to a third-party API without explicit disclosure can cause unintended data exposure and informed-consent failures.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill invokes sensitive capabilities including environment file access and modification, browser automation, and command execution, but does not declare any tool scope or allowed-tools boundary. That makes the effective privilege set implicit and harder to review, increasing the chance the agent will overreach into host or credential-handling actions beyond user expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill saves uploaded video files and transcript outputs to local directories and later supports archiving them, but gives no upfront warning about retention, storage location, or possible sensitivity of spoken content. This can lead to unintended persistence of personal, copyrighted, or confidential material.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill tells the agent to ask the user for a raw Groq API key in chat and then write it into a local .env file. Collecting and handling credentials directly in the conversation creates a clear secret-exposure risk through chat logs, model context, and accidental reuse or disclosure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes generic terms such as "转录", "transcribe", and "视频转文本" that are not unique to Douyin and can match many unrelated user requests. This can cause unintended invocation of a skill that has access to powerful tools like browser and exec, increasing the chance of unnecessary exposure to untrusted links or files and accidental execution paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script uploads full audio content to Groq or OpenAI for transcription, but the user-facing flow does not clearly warn that media leaves the local machine and is processed by a third party. Because Douyin videos and local files may contain personal, copyrighted, or sensitive information, silent remote transmission creates a real privacy and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The transcription request hard-codes the language parameter to 'zh', which enforces Chinese-language processing regardless of the user's actual content or preference. The file does not present this as an opt-in locale choice or explain a compliance-bound reason for restricting processing to Chinese only.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

After transcription, the script sends transcript text to Groq again for punctuation and formatting without a separate disclosure that another third-party processing step occurs. This expands data exposure beyond the minimum necessary operation and may transmit sensitive speech-derived text even when the user only expected speech-to-text processing.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/transcribe.js:32

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/transcribe.js:457