Back to skill

Security audit

Deepsop Douyin 协作台

Security checks for vulnerabilities and agentic risk

Overview

The skill is for Douyin automation, but it gives the agent broad authority to download and run unverified third-party code and to publish to a live account with weak user controls.

Review carefully before installing. This skill can change your local environment, download and run third-party code through mirrors, install browser automation components, use local Douyin session data, and publish content publicly. Prefer a version that pins and verifies the external repository, disables untrusted mirror fallback by default, and requires explicit confirmation before every login or publish action.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/runtime-requirements.md:58
Finding

Automatic Retrieval and Execution of Unverified Third-Party Code

Content
View full analysis
# Try 2: gh-proxy.org git clone https://gh-proxy.org/https://github.com/dreammis/social-auto-upload.git # Try 3: gh-proxy.com git clone https://gh-proxy.com/https://github.com/dreammis/social-auto-upload.git # Try 4: gitmirror git clone https://hub.gitmirror.com/https://github.com/dreammis/social-auto-upload.git ``` The downloaded source and dependencies are subsequently prepared and executed: ```bash cd # Copy example configuration # Windows copy conf.example.py conf.py # macOS / Linux cp conf.example.py conf.py # Synchronize dependencies uv sync --python 3.12 ``` ```bash uv run --project python sau_cli.py --help ``` The behavior is made mandatory by `SKILL.md:27-33`: ```markdown 1. Check whether `~/.openclaw/social-auto-upload` exists 2. If it does not exist, automatically clone + `uv sync` 3. Once ready, all calls use `uv run --project ~/.openclaw/social-auto-upload python sau_cli.py douyin ...` 4. Do not directly use `sau douyin ...` 5. On network failure, the agent must automatically retry through `gh-proxy.org` / `gh-proxy.com` / `hub.gitmirror.com` ``` ### Technical Analysis The installation workflow retrieves mutable executable source from external repositories and proxy services without pinning an audited commit, validating a cryptographic checksum, checking a signed release, or confirming that mirror content is identical to the intended upstream repository. The first fallback points to `gitee.com/lonycn/social-auto-upload`, which is under a different repository owner from the intended GitHub sour ...[truncated 2051 chars]
Remediation
View remediation

other

Warning
Location
scripts/examples/douyin_cli_template.py:30
Finding

Executable Examples Automatically Attempt Real Content Publication

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (17)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/cli-contract.md (reported line 1)May include surrounding context.

md
# 假设 social-auto-upload 已 clone 到 $SAU_HOME,且已经跑过 `uv sync --python 3.12`。
$SAU_HOME = "$env:USERPROFILE\.openclaw\social-auto-upload"

# PowerShell examples for the installed sau CLI.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/runtime-requirements.md (reported line 1)May include surrounding context.

md
# 假设 social-auto-upload 已 clone 到 $SAU_HOME,且已经跑过 `uv sync --python 3.12`。
$SAU_HOME = "$env:USERPROFILE\.openclaw\social-auto-upload"

# PowerShell examples for the installed sau CLI.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/troubleshooting.md (reported line 1)May include surrounding context.

md
# 假设 social-auto-upload 已 clone 到 $SAU_HOME,且已经跑过 `uv sync --python 3.12`。
$SAU_HOME = "$env:USERPROFILE\.openclaw\social-auto-upload"

# PowerShell examples for the installed sau CLI.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/examples/douyin_commands.ps1 (reported line 1)May include surrounding context.

text
# 假设 social-auto-upload 已 clone 到 $SAU_HOME,且已经跑过 `uv sync --python 3.12`。
$SAU_HOME = "$env:USERPROFILE\.openclaw\social-auto-upload"

# PowerShell examples for the installed sau CLI.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README advertises automatic cloning and dependency setup without clearly warning that local system state will be modified and third-party code will be introduced. In this skill context, that is security-relevant because it expands the attack surface through supply-chain exposure and may lead users to approve execution they do not fully understand.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README materially understates the skill's behavior by claiming it only reads user-specified video files, while elsewhere stating it will automatically clone an external repository and prepare dependencies. This can mislead users and reviewers about filesystem changes, code provenance, and the true trust boundary, increasing the chance that unreviewed third-party code is executed without informed consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document says the skill contains only example template scripts, but the rest of the README describes an operational wrapper that automatically fetches and runs an external upload tool. This discrepancy obscures the executable nature of the skill and may cause users to treat it as passive documentation when it actually introduces code execution and supply-chain risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill clearly instructs the agent to perform shell-based operations such as cloning a repository, syncing dependencies, and running Python commands, but it does not declare any explicit tool scope or allowed tools. This weakens enforcement and review boundaries, making it easier for an agent or platform to execute powerful commands without transparent permission gating.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that first use will automatically clone external code and prepare dependencies, while explicitly discouraging manual installation, but it does not present this as a clear user-facing security warning. Automatically fetching and executing third-party code expands the trust boundary and can expose the environment to supply-chain compromise or unexpected code execution without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to automatically retry failed GitHub access using third-party mirror domains, but it does not warn the user that code may be downloaded from alternative infrastructure outside GitHub. This is more dangerous than normal dependency installation because mirrors may bypass expected integrity and provenance checks, increasing the risk of tampered code or silent redirection to untrusted sources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document defines login and content publishing flows, including immediate posting when no schedule is supplied, but does not require an explicit user warning or confirmation before actions that can change account session state or publicly publish content. In an agent context, this increases the risk of unintended logins, cookie refreshes, or accidental public posting because the operator may treat the CLI as routine automation rather than a high-impact action.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file is entirely written as prescriptive agent guidance in Chinese, and it does not indicate that the user may choose another language or locale. Under the policy rule, forcing a specific language without opt-in is a natural-language policy concern unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/examples/douyin_cli_template.py (reported line 22)May include surrounding context.

python
def run_command(command: list[str]) -> None:
    print("Running:", " ".join(shlex.quote(part) for part in command))
    subprocess.run(command, check=True)


def main() -> None:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script demonstrates real login, account checking, and upload commands against Douyin without any inline warning, confirmation step, or disclosure that it will perform network actions and publish content under a user account. In the context of an agent skill for automated social-media operations, this increases the risk of unintended authentication, account actions, or accidental content publication if a user or higher-level agent runs the example as-is.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script includes a douyin upload-note workflow that posts image/note content, while the skill metadata describes the capability as automatic Douyin video upload. This scope mismatch is dangerous because users or higher-level agents may invoke the skill expecting only video actions, but the script can publish a different content type to a real social-media account, expanding the write surface and increasing the chance of unintended or unauthorized posting.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README is entirely in Chinese and instructs the user to speak requests in Chinese, but it does not indicate that this locale restriction is optional or justified. This can violate language/locale policy when a skill implicitly requires a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

该 markdown 文件全文以中文编写,未见任何允许用户选择语言或说明该技能仅面向特定中文环境的文字。根据规则,强制单一语言且无用户 opt-in 的自然语言策略约束可构成语言/区域政策问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.