Back to skill

Security audit

TikTok Creator Pipeline

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it includes a high-impact command-injection flaw in its transcription path and runs background local processes with limited user control.

Review before installing. Only use this skill with links and files you trust, avoid the CPU/background Whisper path until shell=True is removed, confirm paid TikHub calls before downloads, and be aware that scraped comments/user data and transcripts can be written locally while identifiers and URLs are sent to TikHub.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/tikhub.py:286
Finding

Shell Command Injection in Background Whisper Transcription

Content
View full analysis
{log_file} 2>&1 &" print(f"🚀 Whisper 后台转写启动,日志: {log_file}") subprocess.run(nohup_cmd, shell=True) ``` ### Technical Analysis The public `whisper_transcribe` function constructs a command by joining arguments into one shell command string and executes it with `shell=True`. Parameters such as `audio_path`, `model`, and `language` are inserted without shell escaping, quoting, or allowlist validation. Because the command is interpreted by a shell, metacharacters contained in an attacker-controlled argument can terminate or alter the intended `whisper` command and introduce additional commands. Using `os.path.basename()` for the log filename does not protect the original `audio_path` included in `cmd`. The synchronous branch uses an argument list without `shell=True` and is not affected by this specific flaw. ### Attack Path 1. An attacker obtains influence over an audio path passed to `whisper_transcribe`, directly or through an integration that accepts user-selected filenames. 2. The attacker supplies a path containing shell metacharacters and an additional command, for example a filename structured as `audio.wav; attacker_command; #`. 3. `whisper_transcribe` places that value into `cmd`. 4. The function joins `cmd` into `nohup_cmd` without escaping. 5. `subprocess.run(..., shell=True)` asks the operating-system shell to interpret the resulting text. 6. The shell executes the injected command with the same operating-sy ...[truncated 529 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned and Unnecessary Third-Party Dependencies

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (26)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The function concatenates untrusted parameters into a shell command and executes it, enabling tool-parameter abuse and arbitrary command execution. In this skill's context, parameters can derive from file paths and transcription options, and the detached execution makes exploitation harder to detect and stop.

Content

Scanner excerpt · scripts/tikhub.py (reported line 307)May include surrounding context.

python
log_file = f"/tmp/whisper_{os.path.basename(audio_path)}.log"
        nohup_cmd = f"nohup {' '.join(cmd)} > {log_file} 2>&1 &"
        print(f"🚀 Whisper 后台转写启动,日志: {log_file}")
        subprocess.run(nohup_cmd, shell=True)
        print(f"📝 文字稿将保存到: {output_path}")
        print(f"⏱️  medium 模型 CPU 转写 1 分钟音频约需 1-2 分钟,请耐心等待")
        return output_path

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill documents and encourages network access, shell execution, and file-writing behaviors, but it declares no explicit tool scope or permission boundaries. In an agent environment, that mismatch can enable broader-than-expected execution, making it easier for the skill to scrape data, download media, and write files without clear user-facing constraint or platform enforcement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation description is broad enough to trigger on many ordinary requests involving videos, comments, user info, downloads, or API usage. That increases the chance of unintended invocation of a skill that performs scraping, downloading, and transcription, potentially causing privacy issues, external data transfer, or paid API calls without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill promotes scraping user information, fan lists, comments, and sending media through external processing pipelines, but it does not clearly warn users about privacy, consent, copyright, retention, or third-party transmission risks. In this context, omission is dangerous because the skill is specifically designed to collect and process potentially sensitive third-party data at scale.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill depends on transmitting data to an external TikHub API endpoint, which creates third-party exposure for URLs, identifiers, metadata, and potentially downloaded-media workflow inputs. External transmission is expected for this skill, but it remains security-relevant because users are not clearly warned about what data leaves the local environment or when paid/sensitive API operations occur.

Content

Scanner excerpt · SKILL.md (reported line 160)May include surrounding context.

md
- **视频下载计费**:每次调用付费端点都会被计费,注意余额
- **转写速度**:mlx-whisper(Apple GPU)> openai-whisper small(CPU)> openai-whisper medium(CPU)
- **faster-whisper 不支持 Apple MPS**:不要用!
- **API 文档**:https://api.tikhub.io/docs(Swagger UI)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The inline comments state that GPU mode returns text content while CPU mode returns a path, but the code then assigns the GPU-mode return value to text_path and stores it under path while also taking len(result) as text length. This is an active contradiction in the documentation/comments around what the function returns, which can mislead operators about the skill's actual behavior and outputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module docstring is entirely Chinese and includes locale-specific guidance such as using a China-domain endpoint for domestic users, while later functions also default transcription language to Chinese. This creates a language/locale constraint that is not presented as an explicit user choice or clearly justified as a region-specific-only tool.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/tikhub.py (reported line 52)May include surrounding context.

python
"""通用 POST 请求"""
    for i in range(retries):
        try:
            resp = requests.post(f"{BASE_URL}{endpoint}", headers=HEADERS, json=json_data, timeout=30)
            if resp.status_code == 429:
                print(f"⚠️ 频率限制,等待 5 秒...")
                time.sleep(5)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest frames the skill as a TikHub API-based multi-platform scraping/downloading tool, and mentions link-to-text conversion as a Whisper pipeline. However, the implementation invokes local executables (ffmpeg, whisper) and even launches a background shell command with nohup, which is a materially broader capability than simple API use or download logic. This local process execution is not an obvious requirement of a normal API wrapper and is security-relevant because it expands the skill's operational power on the host.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/tikhub.py (reported line 262)May include surrounding context.

python
"""
    if not output_path:
        output_path = video_path.rsplit(".", 1)[0] + ".wav"
    result = subprocess.run([
        "ffmpeg", "-i", video_path, "-vn",
        "-acodec", "pcm_s16le", "-ar", "16000", "-ac", "1",
        output_path, "-y"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The whisper_transcribe function sets language: str = "Chinese" by default, which forces a specific language behavior for transcription. The policy allows locale constraints only when the user is given a choice or the restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/tikhub.py (reported line 287)May include surrounding context.

python
model: tiny/base/small/medium/large,medium 精度速度平衡好
        language: 语言代码,Chinese
        output_path: 可选,文字稿输出路径
        background: True 用 nohup 后台跑(推荐,CPU 慢);False 同步等待
    返回: 文字稿文件路径(后台模式立即返回路径,不等待完成)
    """
    if not output_path:

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

Using nohup to launch a background process creates execution that persists after the initiating session returns, reducing visibility and control. In this skill, that persistence combines poorly with shell=True and user-influenced command construction, increasing the chance of unnoticed abuse and resource consumption.

Content

Scanner excerpt · scripts/tikhub.py (reported line 305)May include surrounding context.

python
if background:
        log_file = f"/tmp/whisper_{os.path.basename(audio_path)}.log"
        nohup_cmd = f"nohup {' '.join(cmd)} > {log_file} 2>&1 &"
        print(f"🚀 Whisper 后台转写启动,日志: {log_file}")
        subprocess.run(nohup_cmd, shell=True)
        print(f"📝 文字稿将保存到: {output_path}")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
99% confidence
Finding

This builds a shell command string from user-influenced values and executes it with shell=True, creating a classic command-injection path. An attacker controlling audio_path, model, language, or output-derived values could inject shell metacharacters and run arbitrary commands, and the nohup/background behavior makes the execution persistent beyond the immediate session.

Content

Scanner excerpt · scripts/tikhub.py (reported line 307)May include surrounding context.

python
log_file = f"/tmp/whisper_{os.path.basename(audio_path)}.log"
        nohup_cmd = f"nohup {' '.join(cmd)} > {log_file} 2>&1 &"
        print(f"🚀 Whisper 后台转写启动,日志: {log_file}")
        subprocess.run(nohup_cmd, shell=True)
        print(f"📝 文字稿将保存到: {output_path}")
        print(f"⏱️  medium 模型 CPU 转写 1 分钟音频约需 1-2 分钟,请耐心等待")
        return output_path

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/tikhub.py (reported line 312)May include surrounding context.

python
print(f"⏱️  medium 模型 CPU 转写 1 分钟音频约需 1-2 分钟,请耐心等待")
        return output_path
    else:
        result = subprocess.run(cmd, capture_output=True, text=True)
        if result.returncode != 0:
            print(f"❌ Whisper 错误: {result.stderr[-300:]}")
        print(f"📝 转写完成: {output_path}")

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The mlx_whisper_transcribe function hardcodes language: str = "zh" as its default, constraining transcription to a specific locale. There is no accompanying opt-in flow or strong justification that this skill is exclusively for a Chinese-only compliance or regional context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The example hard-codes language="zh" for transcription, which imposes a specific language setting in the natural-language guidance without offering a user-selectable option. The policy allows locale constraints only when optional or clearly justified; here the documentation presents Chinese as the default behavior without an explicit choice mechanism.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency list includes requests without a version pin, making builds non-reproducible and allowing installation of different releases over time. In a skill that fetches external content and may process attacker-controlled URLs, this increases supply-chain risk and makes it impossible to verify whether a vulnerable requests version is being installed.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests
openai-whisper
mlx-whisper
ffmpeg

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
97% confidence
Finding

requests has multiple known advisories, and because no version is pinned there is no way to determine whether deployment will install a fixed or vulnerable release. This is more dangerous in this skill because it is explicitly designed to retrieve external platform data and may encounter attacker-influenced URLs or redirects, increasing the chance that a requests flaw could be exercised.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
90% confidence
Finding

openai-whisper is unpinned, so installations may pull different versions with different transitive dependencies and security posture. Because this skill performs download-to-audio-to-transcription processing on untrusted media, dependency drift can expose the environment to newly introduced bugs or malicious package compromise.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests
openai-whisper
mlx-whisper
ffmpeg

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
89% confidence
Finding

mlx-whisper is also unpinned, which creates the same reproducibility and supply-chain integrity problem. In a media-processing skill, untrusted audio/video inputs make parser-related dependency issues more relevant, so installing an unexpected version increases operational risk.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
requests
openai-whisper
mlx-whisper
ffmpeg

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
60% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
requests
openai-whisper
mlx-whisper
ffmpeg

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The top-level natural-language description is written as a fixed Chinese label ("抖音/TikTok 数据爬取工具") with no indication that language or locale is configurable. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation, and this file does not document any justified region-specific requirement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

In comments mode, the script collects comment data and saves it to comments_<aweme_id>.json. Although it prints the filename after completion, there is no upfront warning in the usage text, parser description, or argument help that this mode persists scraped user content to disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The user-videos mode fetches data associated with a Douyin account and writes it to user_videos_<unique_id>.json. The script announces the save only after the operation, but does not disclose in advance via documentation, comments, or help text that account-related data will be stored locally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.