Back to skill

Security audit

douyin录播并自动上传

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently automates uploading and optionally publishing a local video to Douyin using the user's logged-in browser session.

Install only if you are comfortable giving the skill control of a logged-in Douyin Creator Center browser tab. Review the file path, title, visibility, --publish setting, and CDP endpoint before each run; use --publish false when you want to upload and inspect before posting.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.