Back to skill

Security audit

一键收藏抖音B站视频到你的飞书多维表格

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent video-to-Feishu purpose, but its shell-based URL handling and tool declarations create real review-worthy risk before installation.

Review this skill before installing. Use it only with trusted video links, add explicit confirmation before Feishu writes, validate URLs with exact HTTPS host allowlists, and avoid shell interpolation for user-supplied URLs. The skill should also align its allowed-tools with the actual tools it asks the agent to run.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:58
Finding

Command Injection Through Shell-Interpolated Video URLs

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 58-78
Vulnerability Type: Shell command injection through untrusted URL interpolation
Risk Level: High

Vulnerable Code

bash
# Use dokobot to read the page with automatic JavaScript rendering
dokobot read "<url>" --local --timeout 5000

The Skill also instructs substitution of a supplied Douyin short link into this command sequence:

bash
# Douyin short link → complete URL
FULL_URL=$(curl -sL "https://v.douyin.com/xxx" -w "%{url_effective}" -o /dev/null)
# Then pass it to dokobot
dokobot read "$FULL_URL" --local --timeout 5000

Technical Analysis

The Skill accepts a video URL controlled by the user and instructs the Agent to place that value into Bash command text. Enclosing the URL in double quotes does not make shell interpolation safe. Bash still evaluates command substitutions such as $(command) and backtick expressions inside double-quoted strings. A quotation mark in a value copied directly into the command can also terminate the intended argument and introduce additional shell syntax.

The documented platform check only looks for strings such as douyin.com, v.douyin.com, bilibili.com, or b23.tv. It does not require structured URL parsing, an exact hostname match, a fixed HTTPS scheme, or rejection of shell metacharacters. Consequently, a crafted value may appear to reference an accepted platform while carrying shell syntax.

The short-link workflow introduces an additional trust boundary. It follows redirects with curl -L and passes the resulting URL to another command without requiring validation of the final scheme and hostname. Although quoting the expanded FULL_URL prevents ordinary shell syntax contained in the variable from being re-evaluated, the original user value remains dangerous if the Agent substitutes it directly into the curl command template. Redirect validation is also necessary to prevent retrieval from unintended destinat ...[truncated 1589 chars]

Remediation
View remediation

Remediation Suggestions

  1. Do not construct shell commands by inserting user-controlled URLs into command text. Invoke the required program through an API that accepts an argument array without passing through a shell.

  2. If Bash cannot be avoided, pass the URL as a positional parameter rather than embedding it in the script:

bash
bash -c 'exec dokobot read "$1" --local --timeout 5000' -- "$VALIDATED_URL"

The tool interface must bind VALIDATED_URL as a separate argument; the Agent must not generate the outer command by textual concatenation.

  1. Validate URLs with a structured URL parser before invoking any network utility:

    • Permit only the https scheme.
    • Require an exact hostname from an explicit allowlist.
    • Reject usernames, passwords, malformed ports, control characters, and ambiguous encodings.
    • Do not use substring matching to validate hosts.
    • Normalize the hostname before comparison.
  2. Validate redirects independently. For short links, inspect every redirect target or at least the final effective URL and reject destinations outside the explicitly approved Douyin or Bilibili host allowlist. Consider limiting the number of redirects.

  3. Reject shell metacharacters as defense in depth, including command-substitution syntax, backticks, unescaped quotation marks, newlines, and null bytes. This must supplement, not replace, shell-free process invocation.

  4. Reduce tool permissions to the minimum necessary. Remove unused Bash(node *), Bash(mkdir *), and Bash(rm *) permissions. Prefer narrowly scoped network and Feishu APIs over general Bash execution.

  5. Align the allowed-tool declaration with the documented workflow. Explicitly define narrowly constrained access for required tools instead of relying on broad shell permissions or documenting commands that are absent from the allowlist.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include broad everyday expressions like '收藏视频' and '帮我整理这个视频', which can cause the skill to activate on ambiguous user requests. Because the skill performs external fetching and writes records to Feishu, accidental invocation can lead to unintended network access and data entry without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description explains automated fetching, summarization, classification, and insertion into Feishu, but does not clearly warn users that provided links and extracted content will be transmitted to external services and persisted in a remote table. This lack of notice weakens informed consent and increases the chance of unintentionally storing sensitive or private content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs use of external executables (dokobot, lark-cli) that are not declared in allowed-tools, creating a gap between the manifest’s stated execution surface and the behavior the operator is told to perform. This undermines tool allowlisting, reduces auditability, and may cause data to be sent to unreviewed components for page rendering or record insertion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

整个技能描述和输出格式均默认使用中文,且未说明是否支持用户选择其他语言或这是一个仅面向中文场景的限定工具。按语言/locale 策略,强制特定语言而无用户选择或明确 justification 可能构成自然语言策略问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.