T09 · Insecure Skill Coding Practices
- Location
tiktok-get-stream.js:188- Finding
Shell Command Injection in the Streamlink Fallback
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This TikTok live-monitor skill fits its general purpose, but it needs Review because it runs underdocumented external tools and contains command-execution and leftover-log risks.
Review before installing. Use only in a constrained, low-privilege environment, do not pass untrusted usernames or quality values, and expect it to contact TikTok, inspect network responses, invoke external media tools, and write temporary output. The command construction, eval usage, and temp-file handling should be fixed before routine use.
tiktok-get-stream.js:188Shell Command Injection in the Streamlink Fallback
tiktok-get-stream.js:200Shell Command Injection in the yt-dlp Fallback
extraction-methods/extract-tiktok-yt-dlp.sh:27Arbitrary Command Execution Through eval in the yt-dlp Script
extraction-methods/extract-tiktok-yt-dlp.sh:8Predictable Temporary Directory Permits Symlink Attacks and Leaves Sensitive Logs
The skill claims Playwright-based live monitoring and FLV capture but reportedly uses additional undeclared extraction methods such as streamlink and yt-dlp. Undeclared execution paths and dependencies are a security concern because they change the trust boundary, may invoke external binaries, and can surprise users or policy systems that approved the skill based on the written description.
The skill claims Playwright-based live monitoring and FLV capture but reportedly uses additional undeclared extraction methods such as streamlink and yt-dlp. Undeclared execution paths and dependencies are a security concern because they change the trust boundary, may invoke external binaries, and can surprise users or policy systems that approved the skill based on the written description.
The skill claims Playwright-based live monitoring and FLV capture but reportedly uses additional undeclared extraction methods such as streamlink and yt-dlp. Undeclared execution paths and dependencies are a security concern because they change the trust boundary, may invoke external binaries, and can surprise users or policy systems that approved the skill based on the written description.
The skill claims Playwright-based live monitoring and FLV capture but reportedly uses additional undeclared extraction methods such as streamlink and yt-dlp. Undeclared execution paths and dependencies are a security concern because they change the trust boundary, may invoke external binaries, and can surprise users or policy systems that approved the skill based on the written description.
Without declared permissions the skill's intent is opaque and cannot be validated.
The description advertises recording streams to disk and capturing stream URLs from network traffic without an explicit user warning about surveillance, storage, and privacy implications. In this context, that omission is significant because the skill handles potentially sensitive media capture and network-derived identifiers, so users need clear notice before enabling it.
The script captures and persists full yt-dlp stdout/stderr and enables --write-info-json, while the comments explicitly note that output fields such as cookies/headers may exist. In a monitoring/recording context, retaining verbose extractor output and metadata can disclose session tokens, request headers, stream URLs, or account-related metadata beyond what is needed to return a live stream URL.
The code builds shell command strings with untrusted CLI-derived values (username, quality) and executes them through bash via child_process.exec. This creates command injection risk if an attacker can supply crafted arguments, and it also expands the skill's capability from browser/network monitoring into arbitrary subprocess execution.
This code creates a temporary directory and later stores stdout/stderr logs there, which is a file-write operation. Although the script has some debug logging, there is no warning in comments or usage text that running it will create files under /tmp and retain potentially sensitive command output.
Using --write-info-json causes yt-dlp to create metadata files on disk that may contain more information than necessary for simple live URL extraction, including stream metadata and potentially sensitive request-related fields depending on extractor behavior. In this skill's automation context, undisclosed metadata persistence increases exposure because recordings/monitors often run unattended and may leave artifacts behind.
The page-readiness logic first waits for the German tab label "Erneute Veröffentlichungen" and only falls back to English later, indicating an implicit locale preference embedded in the skill. This is a natural-language locale assumption that is not exposed as a user choice or documented as a region-specific constraint.
The file contains natural-language comments and UI-matching logic centered on German phrases such as "DSGVO", "Bei TikTok anmelden", and "Jetzt nicht", alongside some English variants. This effectively bakes in a language/locale assumption for page handling without any user opt-in or documented locale selection, which matches the language/locale policy concern for natural-language content.
No suspicious patterns detected.