Back to skill

Security audit

抖音视频转文字

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real Douyin/video transcription tool, but its command execution and API-key handling create material security risk.

Review before installing. Do not paste API keys into normal chat; configure secrets through a safer local or platform secret mechanism. Run only in a sandboxed environment, avoid sensitive videos or private account sessions, and patch the script to use `execFileSync`/argument arrays plus strict URL and file-path validation before processing untrusted links or files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/transcribe.js:103
Finding

Shell Command Injection Through Untrusted URLs and File Paths

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (30)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 53)May include surrounding context.

bash
cd ~/.openclaw/workspace/skills/douyin-transcribe
cp .env.example .env

编辑 .env,填入你的 Groq API Key:

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared purpose says the skill transcribes Douyin links or video files, but the instructions also include credential handling, browser automation, media extraction, local file operations, external API calls, and shell execution. This description-behavior gap can mislead users and policy systems about the real trust boundary and data flows.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The skill instructs the agent to inspect the .env file in the skill directory, which is a credential-bearing file by design. Reading such a file gives the agent access to secrets and increases the chance of accidental disclosure through logs, outputs, or prompt leakage.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

当用户第一次触发这个 Skill 时,你需要先检查环境是否就绪。 按以下顺序检查,缺什么就引导用户补什么:

检查 1:.env 文件是否存在

检查 Skill 目录下是否有 .env 文件:

text

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The explicit read operation against <skill目录>/.env is credential access, not just normal configuration handling. In a skill context, this is especially risky because LLM agents can inadvertently expose secret values when summarizing file contents or debugging setup failures.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

检查 Skill 目录下是否有 .env 文件:

text
read: <skill目录>/.env

如果不存在,从 .env.example 复制一份:

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

Copying a template into a live .env file is not secret theft by itself, but in this skill it is part of a broader pattern of agent-managed credential storage and handling. Having the agent create and manage the secret-bearing file expands the trusted surface and encourages unsafe secret workflows.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

如果不存在,从 .env.example 复制一份:

text
exec: cp <skill目录>/.env.example <skill目录>/.env

检查 2:Groq API Key

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instructions explicitly tell the user to send a secret API key in natural language and direct the agent to read and write that secret into a .env file. This is a strong sensitive-data handling flaw because it normalizes secret exfiltration into conversation and broadens exposure to logs, prompt history, and local file access.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

md
node scripts/transcribe.js "<用户的原始链接>"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

md
node scripts/transcribe.js "<用户的原始链接>"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 190)May include surrounding context.

md
node scripts/transcribe.js "<用户的原始链接>"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 259)May include surrounding context.

md
const path = require('path');
const https = require('https');

// 加载 .env 文件
function loadEnvFile() {
  const envPath = path.join(__dirname, '..', '.env');
  if (fs.existsSync(envPath)) {

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/transcribe.js (reported line 12)May include surrounding context.

js
const path = require('path');
const https = require('https');

// 加载 .env 文件
function loadEnvFile() {
  const envPath = path.join(__dirname, '..', '.env');
  if (fs.existsSync(envPath)) {

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/transcribe.js (reported line 135)May include surrounding context.

js
const path = require('path');
const https = require('https');

// 加载 .env 文件
function loadEnvFile() {
  const envPath = path.join(__dirname, '..', '.env');
  if (fs.existsSync(envPath)) {

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/transcribe.js (reported line 140)May include surrounding context.

js
const path = require('path');
const https = require('https');

// 加载 .env 文件
function loadEnvFile() {
  const envPath = path.join(__dirname, '..', '.env');
  if (fs.existsSync(envPath)) {

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/transcribe.js (reported line 14)May include surrounding context.

js
// 加载 .env 文件
function loadEnvFile() {
  const envPath = path.join(__dirname, '..', '.env');
  if (fs.existsSync(envPath)) {
    const envContent = fs.readFileSync(envPath, 'utf-8');
    envContent.split('\n').forEach(line => {

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

README 明确写明“支持中文”,整体示例和说明也默认仅面向中文输出,但没有说明这是可配置选项,也未提供用户选择语言/locale 的机制。根据规则,若技能强制特定语言而无用户 opt-in,可构成语言/locale 政策问题。

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 32)May include surrounding context.

Linux:

bash
sudo apt install ffmpeg   # Debian/Ubuntu
sudo yum install ffmpeg   # CentOS/RHEL

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 33)May include surrounding context.

Linux:

bash
sudo apt install ffmpeg   # Debian/Ubuntu
sudo yum install ffmpeg   # CentOS/RHEL

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README instructs users to send audio to Groq for transcription and post-processing but does not clearly disclose the privacy implications of transmitting potentially sensitive voice content and derived transcripts to a third-party API. This can lead users to expose personal, confidential, or regulated data without informed consent, especially since the skill is positioned as easy and free to use.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 45)May include surrounding context.

md
1. 打开 [console.groq.com](https://console.groq.com)
2. 用 Google 或 GitHub 登录(不需要信用卡)
3. 点击 **API Keys** → **Create API Key**
4. 填个名字(如 `douyin`),点 Submit
5. 复制生成的 Key(以 `gsk_` 开头)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 45)May include surrounding context.

md
1. 打开 [console.groq.com](https://console.groq.com)
2. 用 Google 或 GitHub 登录(不需要信用卡)
3. 点击 **API Keys** → **Create API Key**
4. 填个名字(如 `douyin`),点 Submit
5. 复制生成的 Key(以 `gsk_` 开头)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill clearly instructs the agent to read environment files, execute shell commands, launch a browser, and set environment variables, but it does not declare an explicit tool scope or allowed-tools policy. That mismatch increases the risk of overbroad execution and makes it harder for a host platform to sandbox the skill appropriately.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says the skill will automatically transcribe into Chinese text and the title/body repeatedly frame the output as Chinese by default, but there is no opt-in or language selection mechanism. This is a natural-language locale policy issue because the skill mandates a specific output language without giving the user a choice or clearly documenting a justified regional limitation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill asks the user to send a Groq API key to the assistant and then stores it in a local .env file. This turns a transcription workflow into a credential collection and management workflow, exposing sensitive secrets to the model, logs, and any component with access to the working directory.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs users to send their API key directly to the assistant without any warning about secret handling, storage, retention, or exposure. This is dangerous because chat transcripts and local files may be accessible to operators, logs, other tools, or future prompts.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
> 4. 把 `C:\ffmpeg\bin` 添加到系统环境变量 PATH
> 5. 重启终端,运行 `ffmpeg -version` 验证
>
> **Linux 用户:** 运行 `sudo apt install ffmpeg`
>
> 装好了告诉我!

Static analysis

Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/transcribe.js:32

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/transcribe.js:457