Back to skill

Security audit

TikTok Live Monitor

Security checks for vulnerabilities and agentic risk

Overview

This TikTok live-monitor skill fits its general purpose, but it needs Review because it runs underdocumented external tools and contains command-execution and leftover-log risks.

Review before installing. Use only in a constrained, low-privilege environment, do not pass untrusted usernames or quality values, and expect it to contact TikTok, inspect network responses, invoke external media tools, and write temporary output. The command construction, eval usage, and temp-file handling should be fixed before routine use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
tiktok-get-stream.js:188
Finding

Shell Command Injection in the Streamlink Fallback

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
tiktok-get-stream.js:200
Finding

Shell Command Injection in the yt-dlp Fallback

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
extraction-methods/extract-tiktok-yt-dlp.sh:27
Finding

Arbitrary Command Execution Through eval in the yt-dlp Script

Content
View full analysis
&2 # Log command for debugging # Führe yt-dlp aus und fange stdout/stderr auf eval "$COMMAND" 2> "${TMP_DIR}/yt-dlp.stderr.log" > "${TMP_DIR}/yt-dlp.stdout.log" EXIT_CODE=$? ``` The values embedded in the command are populated from externally supplied script arguments: ```bash USERNAME="$1" FORMAT="${2:-best}" LIVE_URL="https://www.tiktok.com/@${USERNAME}/live" ``` ### Technical Analysis The script builds an executable shell program as a string and passes it to `eval`. `eval` causes a second round of shell parsing. Consequently, quotation characters, command substitutions, separators, and other shell syntax supplied through `FORMAT` or `USERNAME` can escape the intended argument boundaries. The vulnerability remains present even if the JavaScript caller is changed to use a safe process API, because the shell script can be called directly and performs its own unsafe evaluation. ### Attack Path 1. An attacker invokes the script directly, or reaches it through an application that passes attacker-controlled arguments safely as individual parameters. 2. The script assigns the malicious input to `USERNAME` or `FORMAT`. 3. The input is embedded in the `COMMAND` string. 4. `eval` reparses the complete string as shell code. 5. Injected shell syntax executes with the privileges of the script process. When called by the current Node.js implementation, the outer `exec` sink may execute injected syntax first; nevertheless, `eval` is an independent command-injection sink. ### Impact Assessment Successful exploitation enables arbitrary local command execution under the ...[truncated 334 chars]
Remediation
View remediation
"${TMP_DIR}/yt-dlp.stderr.log" \ > "${TMP_DIR}/yt-dlp.stdout.log" EXIT_CODE=$? ``` Also: 1. Enforce a fixed allowlist for `FORMAT`. 2. Validate `USERNAME` before constructing `LIVE_URL`. 3. Use `--` where supported to terminate option parsing. 4. Avoid logging complete attacker-controlled commands or signed URLs. 5. Add direct-script security tests to ensure malicious input remains a literal argument. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
extraction-methods/extract-tiktok-yt-dlp.sh:8
Finding

Predictable Temporary Directory Permits Symlink Attacks and Leaves Sensitive Logs

Content
View full analysis
"${TMP_DIR}/yt-dlp.stderr.log" > "${TMP_DIR}/yt-dlp.stdout.log" ``` No cleanup handler is installed, so these files remain after execution. ### Technical Analysis The temporary path uses a timestamp with one-second resolution and is therefore predictable. `mkdir -p` does not guarantee exclusive creation or verify that an existing path is owned by the current user. In a shared environment, another local user can create the anticipated directory before the victim process and place symbolic links at `yt-dlp.stderr.log` or `yt-dlp.stdout.log`. Shell redirection then follows those links and writes using the victim process's permissions. The lack of cleanup also leaves yt-dlp output and error logs in `/tmp`. Those logs may contain profile metadata, operational details, error information, or signed stream URLs. ### Attack Path 1. A local attacker predicts the directory name from the current Unix timestamp. 2. The attacker creates that directory before the script runs. 3. The attacker places a symbolic link at one of the expected log paths, targeting a file writable by the victim account. 4. The victim invokes the script. 5. Output redirection follows the symbolic link and truncates or overwrites the target file. 6. Separately, files not removed after normal or abnormal execution remain available according to their resulting permissions. ### Impact Assessment The symlink attack can overwrite or truncate files writable by the invoking account. If the script runs under a more privileged service account, the affected scope expands to files wr ...[truncated 297 chars]
Remediation
View remediation
&2 exit 1 } chmod 700 "$TMP_DIR" trap 'rm -rf -- "$TMP_DIR"' EXIT HUP INT TERM ``` Further hardening should include: 1. Do not use predictable names under a shared `/tmp` directory. 2. Fail closed if secure temporary-directory creation fails. 3. Apply a restrictive `umask`, such as `umask 077`, before creating logs. 4. Avoid retaining signed stream URLs or other sensitive output longer than necessary. 5. If persistent diagnostics are required, store them in a dedicated, access-controlled application log directory rather than `/tmp`. ]]>
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill claims Playwright-based live monitoring and FLV capture but reportedly uses additional undeclared extraction methods such as streamlink and yt-dlp. Undeclared execution paths and dependencies are a security concern because they change the trust boundary, may invoke external binaries, and can surprise users or policy systems that approved the skill based on the written description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill claims Playwright-based live monitoring and FLV capture but reportedly uses additional undeclared extraction methods such as streamlink and yt-dlp. Undeclared execution paths and dependencies are a security concern because they change the trust boundary, may invoke external binaries, and can surprise users or policy systems that approved the skill based on the written description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims Playwright-based live monitoring and FLV capture but reportedly uses additional undeclared extraction methods such as streamlink and yt-dlp. Undeclared execution paths and dependencies are a security concern because they change the trust boundary, may invoke external binaries, and can surprise users or policy systems that approved the skill based on the written description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims Playwright-based live monitoring and FLV capture but reportedly uses additional undeclared extraction methods such as streamlink and yt-dlp. Undeclared execution paths and dependencies are a security concern because they change the trust boundary, may invoke external binaries, and can surprise users or policy systems that approved the skill based on the written description.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description advertises recording streams to disk and capturing stream URLs from network traffic without an explicit user warning about surveillance, storage, and privacy implications. In this context, that omission is significant because the skill handles potentially sensitive media capture and network-derived identifiers, so users need clear notice before enabling it.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script captures and persists full yt-dlp stdout/stderr and enables --write-info-json, while the comments explicitly note that output fields such as cookies/headers may exist. In a monitoring/recording context, retaining verbose extractor output and metadata can disclose session tokens, request headers, stream URLs, or account-related metadata beyond what is needed to return a live stream URL.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code builds shell command strings with untrusted CLI-derived values (username, quality) and executes them through bash via child_process.exec. This creates command injection risk if an attacker can supply crafted arguments, and it also expands the skill's capability from browser/network monitoring into arbitrary subprocess execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code creates a temporary directory and later stores stdout/stderr logs there, which is a file-write operation. Although the script has some debug logging, there is no warning in comments or usage text that running it will create files under /tmp and retain potentially sensitive command output.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

Using --write-info-json causes yt-dlp to create metadata files on disk that may contain more information than necessary for simple live URL extraction, including stream metadata and potentially sensitive request-related fields depending on extractor behavior. In this skill's automation context, undisclosed metadata persistence increases exposure because recordings/monitors often run unattended and may leave artifacts behind.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The page-readiness logic first waits for the German tab label "Erneute Veröffentlichungen" and only falls back to English later, indicating an implicit locale preference embedded in the skill. This is a natural-language locale assumption that is not exposed as a user choice or documented as a region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file contains natural-language comments and UI-matching logic centered on German phrases such as "DSGVO", "Bei TikTok anmelden", and "Jetzt nicht", alongside some English variants. This effectively bakes in a language/locale assumption for page handling without any user opt-in or documented locale selection, which matches the language/locale policy concern for natural-language content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.