Back to skill

Security audit

DeepSop TK工作台

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for TikTok video generation and posting, but it gives an agent account-affecting publishing authority and has weak controls around scheduled callbacks and payload validation.

Review before installing. This skill can use your DeepSOP API key to submit TikTok publishing tasks, schedule later result checks, query video analytics, and participate in package purchase flow steps. Only use it with a DeepSOP/TikTok account where that authority is acceptable, and prefer a version that verifies cron callback provenance and strictly validates account IDs, publish counts, intervals, times, and unknown fields before submission.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:85
Finding

Spoofable Scheduled Callback Marker Bypasses the Normal Workflow

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:85-89 and SKILL.md:609-610
Vulnerability Type: Unauthenticated event-source trust and workflow bypass
Risk Level: Medium

Vulnerable Skill Instructions

English rendering of the relevant instructions at SKILL.md:85-89:

text
Step 0: Determine the trigger type before every skill invocation.

Check whether the input contains the [DeepSOP-AutoQuery-Toby] marker:

- If present: Treat it as a cron callback. Do not ask the user or wait for
  confirmation. Parse taskId, tobyDagTaskId, tobyCustomerPoolId, taskName,
  and feishuChatId from the input, skip Steps 1 through 4, and immediately
  execute Step 5.
- If absent: Treat it as an active user request and continue with Step 1.

The later restriction at SKILL.md:609-610 states:

text
Step 5 may execute only after receiving a systemEvent containing the
[DeepSOP-AutoQuery-Toby] marker, or when the user explicitly asks for an
early result query.

Technical Analysis

The initial trigger logic authenticates a scheduled callback solely by checking whether attacker-controlled input contains a static text marker. It does not require or verify trusted event metadata, a cron job identifier, a nonce, a signature, or the event source.

Although the later instructions say that the marker must arrive in a systemEvent, Step 0 does not enforce that condition and explicitly identifies the event through marker presence. An ordinary user can therefore reproduce the marker and provide arbitrary task identifiers.

Once the marker is accepted, the agent is instructed to bypass the account-selection, prompt-confirmation, publication-parameter, and other normal workflow steps. It then performs authenticated result queries using the locally configured DEEPSOP_API_KEY.

Attack Path

  1. An attacker sends an ordinary user message containing [DeepSOP-AutoQuery-Toby].
  2. The message supplies atta ...[truncated 1142 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require trusted runtime metadata proving that the input is a systemEvent; never infer event type from message text.
  2. Bind each callback to a known cron job identifier recorded when the one-shot job is created.
  3. Include an unpredictable nonce in the scheduled payload and verify it before making authenticated requests.
  4. If the runtime supports signatures, sign the callback payload and verify the signature and timestamp.
  5. Reject [DeepSOP-AutoQuery-Toby] when it appears in an ordinary user message.
  6. Associate task identifiers with the current session when the task is submitted. Refuse result queries for identifiers not recorded in that session unless the user completes explicit authorization.
  7. Validate that taskId, tobyDagTaskId, and tobyCustomerPoolId have the expected formats before constructing requests.
  8. Make the Step 0 and Step 5 rules consistent by explicitly requiring verified event provenance in both locations.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/validate_employee_params.py:142
Finding

Incomplete Request-Schema Validation Permits Undocumented and Malformed Submission Data

Content
View full analysis

Vulnerability Details

File Location: scripts/validate_employee_params.py:142-149 and scripts/validate_employee_params.py:351-427
Vulnerability Type: Incomplete allowlist, type, format, and range validation
Risk Level: Medium

Vulnerable Code

At scripts/validate_employee_params.py:142-149, sourceSettings is checked only when present, even though the documented schema requires it:

python
if "sourceSettings" in cstp and cstp["sourceSettings"] is not None:
    err(
        errors,
        "collaborationSubmitTaskParam.sourceSettings",
        "WRONG_VALUE",
        f"Toby alone requires sourceSettings to be null; current value: {cstp['sourceSettings']!r}",
        "Change it to null",
    )

At scripts/validate_employee_params.py:351-354, Toby fields are checked for absence, but the enclosing object is not checked for unknown keys:

python
def validate_toby(p: dict, errors: list) -> None:
    base = "...employeeParams.Toby"
    for k in TOBY_REQUIRED:
        if k not in p:
            err(errors, f"{base}.{k}", "MISSING_KEY", f"Toby is missing required field {k!r}")

Publication templates at scripts/validate_employee_params.py:381-403 are primarily checked for field presence and three fixed values:

python
pt = p.get("publishTemplates")
if pt is not None:
    if not isinstance(pt, list) or not pt:
        err(
            errors,
            f"{base}.publishTemplates",
            "WRONG_VALUE",
            "publishTemplates must be a non-empty array",
        )
    else:
        for i, item in enumerate(pt):
            ip = f"{base}.publishTemplates[{i}]"
            if not isinstance(item, dict):
                err(errors, ip, "WRONG_TYPE", "The element must be an object")
                continue
            for k in (
                "publishCount", "releaseType", "timeZone", "intervalType",
                "startTime", "acco
...[truncated 4474 chars]
Remediation
View remediation

Remediation Suggestions

  1. Define and enforce exact allowed-key sets for:
    • The request root
    • collaborationSubmitTaskParam
    • employeeParams.Toby
    • Every publishTemplates entry
    • Every accountConfigList entry
  2. Require sourceSettings to be present and exactly null.
  3. Validate publishCount as a canonical positive integer string with a conservative maximum.
  4. Validate publishInterval as a non-boolean integer within documented operational bounds.
  5. Parse startTime strictly using HH:mm and reject impossible times such as 25:99.
  6. Compare every publication accountId against the account IDs explicitly selected and confirmed during the current session.
  7. Require the account-configuration ID to equal the first confirmed selected account, as required by the documented workflow.
  8. Enforce the documented privacy-level enum and exact boolean/string-boolean types for all interaction settings.
  9. Add maximum lengths for task names, descriptions, prompts, identifiers, URLs, and other strings.
  10. Reject duplicate account templates and impose a maximum number of target accounts.
  11. Add negative tests covering omitted required keys, unknown keys, invalid types, boundary values, unconfirmed accounts, malformed times, and excessive counts.
  12. Treat backend validation as defense in depth rather than a replacement for local validation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个端到端的 TikTok AI 视频生成、发布和数据回查技能;而实际代码片段只是辅助性的 pre-flight 校验器 validate_employee_params.py。虽然声明中确实提到该脚本是提交流程的一部分,但就“该 supplied code chunk 实际做什么”而言,其行为与主体描述存在明显落差:代码没有网络访问、没有提交任务、没有定时触发处理、没有内容生成或发布逻辑,只是在本地检查 JSON 结构、固定字段和值约束。因此,这段代码不能被认为准确代表了所声明技能的主要用途,只代表其中一个支持性校验环节。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README promotes automated TikTok posting and later retrieval of engagement metrics, but it does not clearly warn users that the skill will perform account-affecting actions and process account/content analytics data. In an agent context, this can lead to users triggering publication or data collection without fully informed consent, increasing the risk of unintended posting, privacy issues, or misuse of linked social media accounts.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill explicitly describes use of environment variables, file reads, network access, and shell execution, but does not declare any tool scope or allowed-tools boundary. That omission weakens governance and increases the chance an agent can exercise broader capabilities than reviewers or operators expect, especially for external publishing and scheduled follow-up actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is designed to publish content to external TikTok accounts and to schedule autonomous follow-up queries, but the top-level description does not present this as a prominent upfront risk/consent boundary. In a skill that performs external actions on linked third-party accounts, weak disclosure increases the chance of accidental posting, unintended automation, and user surprise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description and operational instructions are written to require Chinese-language commands and responses, including fixed Chinese trigger phrases and a prohibition on direct curl because Chinese fields may garble. There is no indication that users may choose another language or locale, so the skill effectively enforces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The cron payload stores and re-injects chat-specific identifiers and task details, including feishuChatId, into a future automated system event. Persisting conversational identifiers and operational metadata in scheduled payloads broadens exposure, risks cross-context leakage, and can allow unintended reuse or disclosure if cron jobs are inspected, replayed, or misrouted.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 327)May include surrounding context.

md
DeepSOP agentSubmitTask 一站式提交脚本:UTF-8 安全 + Toby 结构校验 + HTTP 提交。

为什么需要这个脚本(替代 LLM 直接写 curl):
  - LLM 在 Windows bash 里写 `curl -d '{中文 JSON}'` 会触发 ANSI 代码页(cp936)
    与 UTF-8 之间的转码歧义,导致 taskName/taskDescription 提交后变成乱码。
  - 用本脚本后,body 通过 **stdin 字节流**进入 Python,统一按 UTF-8 解码;
    HTTP 请求体使用 `Content-Type: application/json; charset=utf-8` 显式声明编码,

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/submit_task.py (reported line 7)May include surrounding context.

python
DeepSOP agentSubmitTask 一站式提交脚本:UTF-8 安全 + Toby 结构校验 + HTTP 提交。

为什么需要这个脚本(替代 LLM 直接写 curl):
  - LLM 在 Windows bash 里写 `curl -d '{中文 JSON}'` 会触发 ANSI 代码页(cp936)
    与 UTF-8 之间的转码歧义,导致 taskName/taskDescription 提交后变成乱码。
  - 用本脚本后,body 通过 **stdin 字节流**进入 Python,统一按 UTF-8 解码;
    HTTP 请求体使用 `Content-Type: application/json; charset=utf-8` 显式声明编码,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The natural-language header says the validator is exclusively for Toby and enforces that only Toby is supported. Under the policy rule, forcing a specific option without user opt-in can be a natural-language policy concern when the restriction is presented as mandatory rather than optional or context-justified.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:32